Currently, anyone can create an account and choose a password for an email address without verifying they actually own the email address, since there is no "Confirm this is your email address". There is an email that says "Thanks for creating an account" but by then the account is already created. This is a pretty big security flaw.