I agree; it should mention in the registration form, what it is doing, so that it is more clearly.

But about the security issue, the username has to be publicly visible due to how Fossil works, and seems isn't really that much of a problem anyways.