If the user forgets their password, they must answer their hint question (which they hopefully still remember), and supply some other personal information (which is verified against the info they provided upon registering).
Unfortunately, easy to remember == easy to guess (especially if it's someone you know), and "other personal information" is usually not hard to find with some research. Sometimes, you won't know the real identity that goes with someone's online persona, so that won't get you anywhere. Sometimes, you will, though. That solution is probably better than nothing, though.