Originally Posted by FractalizeR
No. Should it?
Yes. There there was a spambot running around the net a few days ago that hit a few hundred websites (including ours). It gained access to hundreds of accounts which it used to spam thousands of PMs to other users by simply using the account username as the account password.
here and
It seems like requiring a password that is different from the username would be a simple hack to add.