At the risk of being ridiculed for my lack of current computer cracking knowledge. Couldn't the account be hacked by breaking into the computer and imposing your computer between the victim and their steam account? Like a more complex man-in-the-middle attack? If the identity is contently changing I mean.
If the Identity is static couldn't you break into computer then slave their computer and use it to access steam, change their password and disassociate their hardware identity? Or is the link permanent?
I'm not very clear on the whole SteamGuard thing.
I'm sure if I can think of these ways without any complex computer knowledge past late 90's hacking procedure information then I'm sure the big hacking rings can come up with something better. I'm also sure that steam have thought of this.
[sub]Disclaimer: The previous post was all theoretical and in no way, shape or form condones anything illegal or suggests that you should go devour some delicious cookies[/sub]
Edit- Dear God typos love to slip in when I'm tired.