No final agreement has yet been reached on what Atom authentication will look like. Authentication was elided from the latest version of the AtomAPI spec (09) based on the belief that such mechanisms belong in their own RFC, and there is a lot to suggest Atom authentication shouldn't be tied to any single mechanism. Having said that, in cases like Bob's where techniques such as HTTP digest authentication aren't available, the method described here would certainly be a good choice.