If you use Basic authentication without SSL, credentials will be sent in clear text that might be intercepted by malicious ...