<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-httpauth-hoba" target="https://datatracker.ietf.org/doc/html/draft-ietf-httpauth-hoba-10">
   <front>
      <title>HTTP Origin-Bound Authentication (HOBA)</title>
      <author initials="S." surname="Farrell" fullname="Stephen Farrell">
         <organization>Trinity College Dublin</organization>
      </author>
      <author initials="P. E." surname="Hoffman" fullname="Paul E. Hoffman">
         <organization>VPN Consortium</organization>
      </author>
      <author initials="M." surname="Thomas" fullname="Michael Thomas">
         <organization>Phresheez</organization>
      </author>
      <date month="January" day="8" year="2015" />
      <abstract>
	 <t>HTTP Origin-Bound Authentication (HOBA) is a digital-signature-based design for an HTTP authentication method.  The design can also be used in JavaScript-based authentication embedded in HTML.  HOBA is an alternative to HTTP authentication schemes that require passwords and therefore avoids all problems related to passwords, such as leakage of server-side password databases.
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-httpauth-hoba-10" />
   
</reference>
