Because people continue to use the same password for every site? It's very much possible for one to look up a username on a database lookup site to get their usernames/emails/passwords from other sites and crossmatch them until they get a combination. I guarantee you one out of every thirty to forty accounts is susceptible to getting hacked via database lookups due to not changing their password frequently and continuing to use the same password.
I do believe that the owner of the forum could change the security, however it works two ways. Some people aren't interested in all the security crap and it's a lot of effort for staff to maintain, etc.
Wrong. My password used here isn't the same as the passwords used elsewhere, I know because newer passwords that I use are far stronger.
So no crossmatch.
By the way, I wonder if you (and everyone else) have actually notice a
pattern.
It appears to me that
NOBODY actually directly address the email confirmation as a viable solution.
If you look at all the past arguments I had with few of them, you will realize
ALL of them actually totally ignore this solution, every time I brought it up.
What are these people trying to hide?
If I were the owner of a forum, and my forum keep getting compromised, and some members suggested email confirmation as a security measure, and I see other websites are using the same feature as part of their security, I would 100% going to use the same measure to solve my problem.
If I were to delay using such measure for years and years, and still not use it as the issue gets critical, I say I would be a complete total shithead.
If you study the behavioral pattern of these people in charge of this forum, you will see they outright ignore such solution, by totally not talking about it.
Something to hide?
Edit:
Do you ever realize this?
Do you ever realize that if email confirmation feature is in place, there would be no problem even if there is crossmatch of passwords between different websites?
Do you know why?
I will let you tell me (or contradict me) why, before I tell you why it works.
Edit #2:
By the way, the only security crap I ever know of, is the excuses that some of you keep giving me to justify not solving the problem.