I dislike being forced to change password without notice, I need some time to come up with a secure, typeable one. Change on next login just results in me reusing an old password or adding a "2" to the current one.
Unless you are being specifically targeted (ie. the attacker knows that you have to repeat the password twice), you mitigate the easiest possible attack: user/password combination from a stolen database.
Although I suppose this was done to force the users to change their password.