Well I'd ask your server provider then if the password protection is encrypted. The normal Apache Web Server password protection doesn't transmit the password you give in an encrypted manner, which is where SSH comes in. Unless the password transmission is encrypted I wouldn't use the password protection for anything overly sensitive or private, but still provides a basic level of security.