Is requiring the old master password to set a new one actually secure?

There is a relevant feature request here: