there are some major flaws with the "Forgot My Password" service that need to be addressed pronto.
Not really flaws in the service IMO. This sort of thing has been going on for years.

The real flaw is in the users not realising that if they answer the questions truthfully then other people will also know the answers.

Just lie.................. it works every time