But if I hacked the account server, I would just edit the database to have no SE token linked, so I wouldnt need your token, or care, because i just directly removed it..... See what I mean?
Then I edit your password to 123456789, login, have fun.
Its like trying to laugh at a burglar because he broke into your house through the window, but doesnt have the keys so he cant do anything when hes in there........