Quote:
	
	
		
			
				
					Originally Posted by  vicz
					 
				 
				Somehow I can't see them doing anything but the last unless pushed. 
			
		 | 
	
	
 I'm sure they include code that can check for the Authorization header, as it would allow them to make the claim that they don't profile [some] password protected sites and use this to satisfy less technical people (eg politicians). They can't rely solely on robots.txt as some sites that use passwords allow google to index them.  
I think we can trust them to respect the authorization header every bit as much as we can trust them to respect their opt-out cookies.