Well, actually from what i read inthe description is that, it shold send the tried password:
Quote:
If someone is close to guessing my password I wanna know about it!
|
So instead of removing the whole password sending (as this was the sense behind the hack) it should be changed, to just send the email to the username tried, but then with the password.
so if you just mistyped your username, then no mail would be sent, as this user doesn't exist or is no admin, but if someone tries to hack into a real admin account, sending the passwords to this' accounts email wouldn't hurt.