On every mediawiki installation it is possible to copy/paste new password set in field "New password:" into field "Retype new password:".
That behaviour should be prevented.
I noted such behaviour in Firefox (2.0.0.16 & 3.0.5) under linux, under Opera 9.63 it is not possible, so it is possible that is browser bug.
Version: unspecified
Severity: normal
URL: http://en.wikipedia.org/w/index.php?title=Special:ChangePassword