http://dauntzs2oj7q36bjd5ttdakaebh6l527dttze4tu363q3etsiulylhad.onion/faq.html
My initial thoughts on this were to disable the login API access on the clearnet gateway, due to the information provided by the API in its existing state as it was used on Recon. Data such as your account username and PGP Key were required to be passed in the API response, which is out of the question completely when passing the data over a clearnet accessible server.