Authentication on the Web
Can send simple username, password.
- But protect them with cryptography.
Clients can have certificates with SSL, but this is rarely used.
- How do users carry their certificates around?
Sites often store authentication data in “cookies”.