> "The other fix would be to use an email address that can't be guessed from the blog address. In other words, the email address is the password."
You'd still be sending your password in the clear, possibly through other peoples mail servers. Not great security.