
You're unclear on this.
They cannot either get into the system or get the password by knowing the answer to the question. They can only cause the user to get their password to be reset. I really don't understand your objection to this. Why don't you explain how you think this compromises the system?
Regards,
-scott anderson
"Welcome to Rivendell, Mr. Anderson..."