> Anyone who uses the API as implemented, however, put's their account at
> risk by passing the user name and password in the URL

+1