Various fixes for XSS and bad crypto. No claim to completeness.