If a user forgets their password, what are you meant to do? If I reset the password via telnet, and they then try to get to their account on the web interface using that new password, it is rejected, although they can collect email using that new password.