I don't think this is a problem, as Q2A uses the userid from the table and not the handle. Even if a user created a handle that mirrored an admin's handle, the password would not be correct for the genuine admin account.
Maybe somebody with more knowledge of the sign-on process can contibute.