The user group right "editmyprivateinfo" allows unregistered users to reset their password. On wikis that allow unregistered users to read only, this is not necessarily obvious, and administrators may inadvertently disable this functionality by removing all rights except "read" from unregistered users. At least I personally was silly enough to do so.
The text appears at Special:ListGroupRights and currently does not correctly describe what "editmyprivateinfo" implies.