That's not about security, your friend is just fucking dumb since he publicize his own password.
Do you think it's clever to write your Bitcointalk username and password, then throw it away to everywhere you want?
This is why before try something, one should understand and learn what he do to prevent about this case may happen due to carelesss.