How is the password sent from browser to server in case of non-ssl transfer?
I want to use bcrypt to hash password+salt before sending.... but it seems there is no javas
Depending on what you are doing, you might be able to offload your authentication to openid.