    .htaccess history and reliability

    I was just wondering what the track record is like for using .htaccess and .htpasswd to protect folders and subdirectories. I am not an Apache prodigy so I figured I'd ask the community.

    Is it considered a good layer of protection when it comes to protecting documents?

    What common mistakes exist when setting up these files? Other than weak passwords of course...


    Well, unless you are using SSL also the passwords can still be sniffed with Dsniff or Ettercap. Normal HTTP authentication just uses base64 encoding, which is reversible.

