Kinda sucks. Absolutely illogical. Domain hijacking would be largely a non-issue if it were push instead of pull. The only possibility would be either password theft/guessing or "social engineering" with your registrar.
Registrar lock helps, but would be unnecessary if it were push.