If you happen to have a web app that stores passwords in clear text or SHA-1 hashed, all is not lost. You can apply further secure hashes to the existing value stored on db and update your authentication validator.
Or invalidate and send an email.
http://reddit.com/r/changelog/comments/lj0cb/reddit_change_p...