I will state the obvious. Don't email me my actual password

I think the password reset links that expire are good. Maybe even make people answer another question or punch in a code that they get as a text message on their cell phones for a 2 factor approach. HTTPS as well.