quote:
Originally posted by WDZ
quote:
Originally posted by matty
Its a crappy system and sends emails to all accounts registered under that email.
Because it doesn't know which account you forgot the password for.
If the form only asked for a username, someone could send me a password reset email without even knowing the address I registered with, which is kinda dodgy. And if it came up with a list of usernames associated with an email address, that would be a privacy issue because there's currently no other way to search for members by email address.
You could very easily have a "click this link to set a new password" link if they just input the username. Thus, if you get it, and it wasn't you, you can click the report link, or do nothing at all.
I don't think entering a username is such a bad idea.