Digits sounds like a good idea in theory, but relying on SMS for password security is like relying SMS for anything. Even if SMS were secure on its own (meaning traffic was encrypted - which it isn't anyway) you still have the problem of people gaining access through a person's cellular provider account. AT&T for example, will allow you to send and receive SMS from your account on their website - an account which is accessible after "verifying" that you own the account by entering your mother's maiden name or dog's birthday (more or less). Point being, this is no more secure than sending my password in plain text to my email.