RFC 2617: HTTP Authentication: Basic and Digest Ac...
RFC-Ref

network


Click on the red underlined text to get to the source

... user authentication, as the user name and password are passed over the network in an unencrypted form. This section provides the specification for a scheme that does not send the password ...


... entity, which is transmitted in cleartext across the physical network used as the carrier. HTTP does not prevent additional authentication ...
... password over the physical network. It is this problem which Digest Authentication attempts to address ...
... The greatest threat to the type of transactions for which these protocols are used is network snooping. This kind of transaction ...



Google
Web
RFC-Ref