I think it should be safer: using login attempts limit, binding to a range of IP, requesting PIN, using OpenID, etc.
Did everyone who has the "united" transaction have a MtGox account name that is also a Forum username?
Yes, I have the same account name.