DevNet Associate (DEVASC) v1.0Understanding and Using APIsMedium

A network security architect is reviewing an internal API that uses Basic Authentication for access. The API is exposed over the public internet. What is the most critical security vulnerability associated with using Basic Authentication in this scenario without additional protective measures?

  1. ADenial of Service (DoS) attacks due to weak rate limiting.
  2. BSQL Injection vulnerabilities in the API backend.
  3. CCross-Site Request Forgery (CSRF) attacks.
  4. DExposure of credentials in cleartext if not transmitted over HTTPS.
Show answer & explanation

Correct answer: D. Exposure of credentials in cleartext if not transmitted over HTTPS.

Basic Authentication sends credentials (username and password) encoded in Base64, which is not encryption. If the connection is not secured with HTTPS (TLS/SSL), these credentials are transmitted in cleartext over the network, making them vulnerable to eavesdropping and interception.

Why the other options are wrong

  • A. DoS attacks are related to API availability and rate limiting, not the inherent security of Basic Authentication's credential transmission.
  • B. SQL Injection relates to database vulnerabilities, independent of the authentication mechanism used at the API layer.
  • C. CSRF is a vulnerability where an attacker tricks a user into performing unwanted actions; while a general web vulnerability, it's not specific to Basic Auth's core weakness.

Basic Authentication Security

Basic Authentication transmits credentials as a Base64-encoded string in the `Authorization` header. This encoding is reversible, meaning credentials are sent in cleartext unless protected by an underlying secure transport layer like HTTPS (TLS/SSL).

  • Credentials are Base64 encoded, not encrypted.
  • Vulnerable to interception if not used over HTTPS.
  • Easy to implement, but inherently insecure over plain HTTP.
  • Should ALWAYS be combined with HTTPS for production use.

Memory trick: Basic Auth's biggest flaw is Cleartext Credentials.

More Understanding and Using APIs questions