> e.g. A fool uses some webservice that asks you to log in with your
> hotmail username and password, so they do, despite the face that this
> webservice is not hotmail.

Not quite what you're saying but tangentially related: many web sites are
confusing to the naive user. They ask you to register using your email
address and a password, without making it clear that they don't mean the
password for the email account. I'm sure more than a few people have been
caught by that. It doesn't mean the website is malicious, but now the
attack front on the password has been expanded.

