danja
3
Yeah, very good point.
Basic Auth on it's own is incredibly insecure.
I remember getting myself in a real mess over trying to secure some web service or other, hassle both ends of the wire. Coincidentally chatted with Hixie (of HTML4 fame). He suggested 'just use Basic Auth with TLS'. Excellent advice. Not totally bullet-proof but for minimal effort, good enough most of the time.