imo this is a must have: - if db is stolen - if its changed how password it transfered / stored (srp maybe?!) user logins, server instantly sends CHANGEPASSWORD ?! (and nothing else) https://github.com/spring/uberserver/issues/9