The HTTP Basic Auth with 2-factor authentication solution is quite solid. The systems behind auth were not tested, because they are shielded well enough as to be not reachable to outsiders.