It doesn't look like posts that are protected with a password are properly protected. If you create a protected post and add a few photos (attachments) people can still access those photos directly without entering the password. For example if the protected post is at:
then people could go directly to:
and they could see the photo without entering the post's password.
Maybe this can be solved by editing my theme - can I put some code around my photo/attachment template that checks if the post is protected or not?
You can also see the tags of protected posts without entering the password.
Another thing - the comments RSS feed. If somebody leaves a comment on a protected post you can see that person's name in the comments RSS feed.