I've seen a rise in websites adopting the practice of non-consensually resetting users' passwords, even if that user is protected by 2FA, if there is suspicious activity in their account or their password has been found elsewhere. This has lead to a ...