The only thing ridiculous in this thread is your naivety and knowledge. There is a
very good reason for which signed messages are being asked for account recovery.
I don't understand why email address can be changed/edited.
Pretty much every service online allows you to do that.
If it is a security vulnerability, then by right it shouldn't allowed to be edited.
It is not.
This would probably have prevented a majority of all the hacking, but why isn't the admin doing it?
.useMethod.preventHacks(IamLeet)

Sigh, people.