Thanks, I'll go read the blog. And you're right -- I don't understand the answer, either. If we "may" not be affected, it tells me that once they see we've authorized Auctiva, they're fine with it -- no phone call.
But the scammers would certainly figure that out and if they hijack an account, they could tell if Auctiva was used in the past pretty easily.
Sounds like a security weakness to me. It would be better if Auctiva DID share user IP addys. That way they could see if someone using an entirely different address may have hijacked.