Authentication still requires the client to have access to the password, where you can just take it and use it for any other purpose.
Unless you're asking every user to manually input a TURN password and they promise not to give it out, you're basically forced to reveal it to every visitor of your site.