Sacrificing users' security just to load ads and generate revenue says a lot about this company's ethics.
A user ID is fine to use as a public key, but it must be paired with something private. Generally some sort of unique, crypographically-secure auth token is fine when combined with forced HTTPS connections.