Casualty, I think this might work, regarding the passwords matter:
It could be like this: you type your username and log in. But, instead of taking you to the user menu, it would take you to a "password screen" or something similar. There, you would type the password you want.
After that, you could PM the user, confirming or not the password he/she chose. That way, if some random person attempted to log someone else's stats, it wouldn't work, since he won't know the NG password to that person's account. Then, if the user don't confirm that password, someone tried to log his stats without his knowledge. =)
- You should warn people NOT to use the same password as they use on their NG accounts. Otherwise... yeah, it's pretty obvious.
- This would involve a lot of manual work, since you can't program your account to send an automatic PM. So you'd have to work quite a lot... everyday.
I hope you understood everything. And I hope it works.