There's a friend finder that requires your email login and password to match emails. Giving a third party site your login details is madness for starters, but imagine what they can do with data matching when they grab all of the email headers...
I remember a thread here some time ago that mentioned something similar, it seems FB stores the contents of your address book and when someone with a matching email address joins it tells THEM about your profile. That way someone who emailed you once can still find you, even if you've changed your email address and have a different profile name. I think that was the issue, anyway.
|