It's good that Linode is taking security seriously, but the pessimist in me wonders; if all it takes to get a password reset site-wide is an attack on a single user, wouldn't that open up a whole new, rather aggravating attack aimed solely at making users fed up with having their password reset all the time?