I would rather they hack for good than bad. After all their are non public hacker groups.
I mean look at the Citi bank hack... I know that is security 101, but COME ON.
Either that, or force the general public to use an openID run by a hack proof source.
Or is this just me?