It was painful to watch, though, and security is a process not a product; five years before authentication credentials could not be stolen by the simplest of XSS attacks suggests a rather broken process.Reading the history there, it looks like there were various complex issues with it, both in terms of should it be implemented, what should it do, and how.