On password sniffing

Bruce Schneier reports on an InfoWorld piece about password security.

Nothin new there, really, but still interesting to see how long these issues have been around without anybody adressing them. I wrote about the deficiencies of cookie based authentication before – so please see this as another plea for a decent identity system that saves us from having to send around plain text passwords.


