in reply to Authentication in web applications
here is a good resource on web security and it covers the stuff you discussed in great detail http://www.technicalinfo.net/papers/index.html