45 karma · joined June 30, 2011
I do not know venerable Khemarato, nor his teachings, but I would humbly suggest that if you’re concerned about people being misled in the Dhamma by that website, it’s better to focus on the content.
I have been working on the project for 6 months now, and I even tweeted the author of that project when he posted it, but he just ignored me haha :(
The MD5 hash is there to mitigate two issues, currently: some (or most) common users won't pay for a certificate, so instead of sending the password in cleartext, it's hashed as an MD5 to avoid exposure—all of this, of course, is no guarantee against MITM. Which leads us to the second issue: most [non–techie] users re–use their password for a _lot_ of things. At least, if the password is intercepted, it won't be reusable.
It's also worth noting that bcrypt is used server–side to store passwords.
Auth (and very possibly a crypto scheme too) is yet to be tackled. Haven't even decided if it should be part of the spec, or left up to each implementer.
Changing "Article" to "Entry"—noted. As for doing away with the custom schema and using the Atom serialization you posted: it's worth noting the protocol is meant to sync with Atom _and_ RSS transparently; to keep things simple and consistent, a middle ground has to be found.
`since_date` is something I'm working on.