Why aren't you encrypting communication with the web client via ssl? Please do this -- I would love to check this out, but transmitting my password in plaintext does not bode well for
treating my other data securely.
Sort of ironically, my attempts to report a bug, and request a feature, have both been stymied; one by a 500 error, and one with a warning from chrome that synchronous xhr requests have been deprecated.