There is, in the identity management circles, much observation to that effect. There have been advocates for encrypting data that passes through the browser (not trusting SSL which encrypts server to browser): i suspect many who made fun of those advocates are having second thoughts as they listen to browser developers talk about intercepting and changing the messages.
no subject