Sure, but designing around the inherent riskiness of user behavior/forgetfulness is an important part of security systems. Users want to be protected, not for blame to be shifted to them.
276 karma · joined May 22, 2010
However, to quote from that post: "The author is correct assuming the attacker has direct access to your password store. This is a big assumption - most organizations go through great lengths to ensure access to say, databases, is levels of security 'deep' beyond just a web login form. Anyway, assuming that this might ever happen to you, how can you address the issue?"