Comment Finding accounts linked to recovery email (Score 1) 99
It seems that one can find out all google accounts associated to a recovery address by simply selecting "I don't know my username" in the google recovery menu.
If the hacker would have known/used this, he could have had access to even more of Mr. Honan's stuff, provided he had more than one gmail accounts which used the same recovery address (and by the looks of it, I'm sure he would have daisy-chained that too).
Google is happy to deliver the associated accounts to the recovery address, with no obfuscation. There's not much hassle to reset those accounts and compromise them as well afterwards.
Although I understand its usefulness, using it for the wrong purpose can turn it against you.
I'm beginning to think recovery emails are bad too..