This could have been achieved by allowing a custom form in the 501 response page.
Where do you put the "Forgot password?" option on a site that uses HTTP auth?
Also in the 501 response.
404 pages have been tailored to great extremes. Why not the 501s?
The "advanced" stuff you can do with HTTP auth [...] isn't a real security win, especially vs. form-auth and TLS.
Digest auth has the distinct advantage that the password is never sent to the server at all. With forms over TLS the password can be intercepted on the server doing the validation. With digest auth this is not possible.
There are a couple minor changes all browsers could make [...]; this would cost many tens of millions of dollars
The real question is, why didn't browsers evolve in that direction to begin with, before too much was invested in form-based authentication?