ok, here's my take... this is classic overthinking. IP whitelists are not some super secret shield if ur traffic isn't encrypted, but they're also not a complete disaster if you keep it locked down and monitor. User:pass? Yeah, more control, but if ur creds are just sitting there unsecured, then...