It's ridiculous that such a system has been let down by something as simple as a forgot password feature! What other forgot password implementation tells you the email address (even a partial one) that they've sent the password reminder to? It's such an obvious privacy hole...