Re: Aha - for once somebody correctly stating that it's the user-name/password combination reuse...
Email as user-name may be a bad idea in terms of re-use, but it has two great advantages:
1) Users remember it
2) It is, by definition, unique. So they only have to go though the hassle of "johndoe123", nope that names is taken, OK then "johndoe124", process the once.
The practice of checking against known easy or spilled passwords is a good idea, as is allowing long passwords that are phrases (and checking for horses & staples as well).