I was recently asked to reset a password because the security requirements for the site have been updated and users have been asked to change their passwords (for users who do not meet the latest standards).
Although the UI only prompted you to provide an email address (to ensure it was an active account) with a password change request, the email link to my inbox was formatted as Sent a Forgotten E-mail page that had the same process as if you clicked on Forgotten E-mail? clicked. Link is often displayed on the login page.
Is it just more convenient to use exactly the same process, or is it simply lazy not to make that distinction, as it clearly affects the user experience? Is this a common practice and if so, why?