Hopefully, people have hard-to-guess passwords -- I mean, it's only "easy" to guess a password if people are using common passwords.
Changing the flow (i.e., so that the password change can't happen until verified on by the old email and/or waiting three days) is probably out of scope for the near future, but as a minimum we could potentially send a notification e-mail to the old e-mail address.
Crystal Sparda
A hacker can easily guess a password, then hack into the account
and instantly change the user's e-mail address
WITHOUT
the original owner even being notified.
The real owner of the account then has no clue that they've been hacked until it is too late.
Shouldn't there be a tool that sends an e-mail to the current e-mail
notifying it that there has been a request to change e-mails?
That way if the account is being hacked, the user at least gets some kind of notice
as to when the hacking took place?