k) Does the application require the user to prove knowledge of the current password, or a minimum of three shared secrets (i.e. pre-established security questions), or be cryptographically authenticated before allowing a password change?
(If shared secrets are NOT used please indicate this in the Comment section, and skip to question q.)