There isn't much more you can do with the key names really. The issue with them using a static key for encrypting the local password is another thing...
> The issue with them using a static key for encrypting the local password is another thing
Actually, it is the thing that I was referring to. Doing things with the key names is another thing -- wily and probably benefits them a little, but it isn't real security.