would be a good thefeft protection if the password would be put in flash1 or even flash0 and even would prevent recovery ;-)
we could also develop a sticker: "theft useless! PSP-THEFT PROTECTION!"
EDIT:
thinking about that, i would make it optional.
REASON:
if you make the bootup-password dependant on the config-file, the theft protection could be bypassed by removing the memstick.
if you make it independant on the config-file, there is a extreme risk of logical brickage (forgot your password? BAD)
