As basic auth sends the header for every single request, it is also vulnerable to CSRF attacks.
Reply on news.ycombinator.com