April 9, 2019
If login/password are not sent - how does UfoDex know this is me logging in?
In fact, UfoDex does not know anything about the client connected until the client announces addresses it owns.
Right after login the client interface generates a proof-of-ownership message, where it announces available public keys under your control. Each pubkey is properly signed and sent to the server.
This is needed for server and other users (you may iteract with in future) to know that you are the one who owns private keys for the announced addresses.
Remember, that private keys (and login/pass) are never revealed to the server.