Information
This policy setting controls whether RSS feeds can be authenticated using the Basic authentication scheme over an unencrypted HTTP connection.
The recommended state for this setting is: Disabled
Note: A developer cannot change this setting through the Feed APIs.
Allowing RSS feeds to use Basic authentication over HTTP will transmit user credentials in plain text, where they could be intercepted en route by a malicious user.
Solution
To establish the recommended configuration via GP, set the following UI path to Disabled :
Computer Configuration\Administrative Templates\Windows Components\RSS Feeds\Turn on Basic feed authentication over HTTP
Note: This Group Policy path is provided by the Group Policy template InetRes.admx/adml that is included with the Microsoft Windows 7 & Server 2008 R2 Administrative Templates (or newer).
Impact:
None - this is the default behavior.