I have to state a few seemingly obvious things for other readers. This is not meant to be a comprehensive list but a short summary.
Neither Parallels Desktop nor Parallels Access are "hacking programs". They don't exploit system vulnerabilities, don't attempt to abuse security and don't hack your credentials.
Users confirm privilege escalation for the installer to do its work, for PD to manipulate bootcamp partition and in some other cases too.
Access and Safari extension are both parts of the program that implement specific functions: authorized remote access and 'open in ie' button.
Parallels don't download and/or install malicious payload. Defining 'malicious' in this context would be too lengthy, however. Parallels only downloads and installs product updates and additional packages required for guest OS (like Windows 8 start button). You can also explicitly request it to download 3rd party antivirus products from security center.
Access doesn't allow remote access without explicit confirmation. The function itself is not even new for PD9. From a practical standpoint it is similar to former Parallels Mobile, but with much better performance and usability.
Parallels doesn't send (or even access) your local passwords, address book or other personal information. Some information is solicited during product registration.
Parallels account created during registration is unrelated to your local or any other accounts. It's primary use is to allow Access client to connect to your computer.
Parallels products do communicate to internet servers on various occasions for legitimate reasons such as registering the product, checking for updates, establishing authorized remote access etc.
At the same time, Parallels Desktop is technically very complicated. To perform its functions and provide services Parallels does need to do many things one could misinterpret as alarming: installing kernel drivers, using advanced CPU features, running privileged network services, establishing remote connections, manipulating network packets, even opening some files, etc. Seeing these things as security violations is uninformed and absurd. Also, it's totally impractical to request explicit authorization on each end every occasion, so we're trying to strike a balance.
While Parallels does listen to criticism, demands, suggestions and other concerns (there's actually ongoing work on Access installer/uninstaller), trojan accusation is by far overreaching at the very least. In fact, it's insulting given that the very purpose of the product is to be useful, not malicious. I'm sorry if someone totally can't tell the difference.