What is the difference between HTTP Digest Authentication and SSL from a performance, security and flexibility point of view?
Some server implementations of HTTP Digest Authentication force you to save the cleartext passwort on the server better implementations save username:realm:MD5(username:realm:password) this has the effect of salting the stored password which gives some security if attackers have obtained the password file.