Is http basic over ssl a realistic solution in most cases?
Would something like this be better?
"Authenticated communication via a browser relies form-based authentication, possibly in conjunction with cookies. If cookies are used, they should include all of the state needed for the server to process them. All other forms of authenticated communication should rely on HTTP Basic or Digest Authentication, typically combined with SSL, possibly with client certificates."
Unless HTTP Basic / Digest are also unsuited for public API's in which case should they not be removed and some other recommendation be made?