perhaps it should not be so easy to reset a password on mtgox then?
perhaps it should be more painful for those who forget their passwords and have to wait
for a call from a mtgox employee who will then quiz them about details of their account?
The yubikey would have saved him from this attack, +1 from the 2 factor auth !