Right you are... The reg hack is easy to do either remotely or by script. We have dozens of PCs that autologon in an industrial setting and the problem we had with the reg hack was that if someone subverted the logon, the password would disappear and an admin would have to be called to re-enter it.

Also, for security reasons, nobody but the admins are supposed to know the password. The machines are locked down with access to external media but if a user could logon at another machine that was not locked down, they could use the external media there to transfer stuff over the network.
_________________________
Give a man a fish and he will be back for more. Slap him with a fish and he will go away forever.