Thanks for the info. When I get home from vacation I will do as you suggested in the linked thread. I have a BTC address in the sig so I should be able to send a signed message. I will send PMs from this account until I get a favorable reply. A warning on the reset page to do by email only to prevent locked accounts would have been nice.
It will not be so and this has been discussed in the thread knight pointed you to
I think this was suppose to be a secret.
Why?
I believe it was secret because the answers to the secret questions were leaked when the forum was hacked, and this data was stored in a way that would be fairly easy to hash the data to get the plaintext answers. Since it would be so easy to hack accounts via secret questions, accounts would need to be manually checked by an admin prior to allowing them to have their password reset this way. It should have been a secret so people who were attempting to hack accounts would not know which attack vectors were not going to work, discouraging people to even attempt to hack accounts.