Tier 0: Primary Email Address(es)
Why? So the other tiers (bank/reputation services) don't have access to reset ALL the other passwords.
Seems a little off:
Yesterday, MegaCorp2020 legally removed $1000 from your safe without permission. You are now motivated to do something about it.
Your options:
1) Do nothing (congratulations laziness)
2) Go through the proper authorities to respond to the wrongdoing (4 years later: after utilizing 80 hours of your time at the beginning of this case, we have determined this was wrong in a class-action lawsuit: you can either have $200 or go against MegaCorp2020 by yourself)
3) Reclaim what was lost on your own (Suspect left a signed blank check under your safe, where your money was, it'll take 2 hours of your time to use it)
4) Respond with revenge (his house has a lot more bullet holes than it used to)
While I certainly understand that ethically/legally the actions may be wrong-- and two wrongs don't make a right-- when someone unethically takes something from their customers, is it surprising that the customers responded with their most logical choice (#3)
Legally: Its probably illegal.
Ethically: There's a lot of gray-- this is a shade of gray; Not a black.
* IANAL: I AM NOT A LAWYER
** Blank check is equivalent to "the signing key is a fixed part of the console's firmware" (use Search Engine).I don't know how accurate it is, but I haven't found any contradicting evidence.
The first rule of intelligent tinkering is to save all the parts. -- Paul Erlich