The admin interface now uses HTTP BA authentication by default. This will prevent unrestricted access to the REST API but the authentication is by no means secure and the HTTPS mode for the REST API should be enabled for all production systems.