Maybe HT should disconnect users when inactivity > 15 mn (in example), by the way you could almost be sure that nobody will use your profile (to change your pass) if you forgot to logout by yourself..?
I think @gala was alluding to some form of bypassing authentication, rather than stealing credentials, such as cookie injection. But to be fair, just adding a ‘current password’ parameter would only aid security in a scenario of auth bypass, which is highly unlikely. We should develop a comprehensive system ( such as multi-factor auth? ) to change a password.