Skip to content

Comment on Using www-authenticate for user authenticationparent

Comments

I've read it's partly for security. If browsers started to let you style and change the login UI then nothing is stopping bad-website.com from making it look like your bank's login site and fooling you. Yes you should be checking the URL, the SSL certs, etc. and not entering your password blindly... but real people don't do that even though they should. So the thinking is the browser will completely control the login form and make it super generic and obvious exactly what website you are logging into.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.