Currently, we don't send the AUTH part of the HELLO command if the password is empty. Using ACLs, it's possible to have a user with a custom username and an empty password (although probably unlikely). I'm adding more tests around this, so I can safely implement this.