I haven't seen the "Enter password box" and I have a hard time imagining why it would exist. Why would they choose to deal with logging into your email, scraping for email addresses(spawning parallel processes etc), risk blacklisting and (more)user hatred (not to mention trying to prove to google you're not a robot)when there is a perfectly good OAuth(2) protocol/spec that along with good google apis to retrieve this data securely (well: http://hueniverse.com/2012/07/oauth-2-0-and-the-road-to-hell...). I agree its still cheap and tacky but not really nefarious.
There is a 10 message / api-key / day limit using the linkedin messaging API I think http://developer.linkedin.com/documents/throttle-limits still annoying getting spammed.