I did not realize that Digest authentication does use a nonce/token in the hash. Now I feel a lot better about the places I've used Digest, and merely think we need to bridge HTTP Authentication and the form-based wankery that actually gets used today.