I believe it's still in effect where all you have to do is enter your email address and you can change your password. The problem with that is, people who have their email address on display can get harrassed by others and not know why their password is getting changed. It should be changed so you need more than just the address to change your password.
Also, I've brought this idea up before, but I didn't see it in the idea box. Some maps have a lot of ridiculously hard names to either read or remember for attacking purposes. It would be a lot easier if you could attack by clicking on your attackING country and then the country you want to attack and select how many armies you want to attack with (somehow). I've made plenty of mistakes in the past by attacking what I thought was one country but it was actually one with a very similar name or something. That's it so far...