RT That's *literally the opposite of best practice* for online account security. Doing this discourages users from setting up secure, randomized passwords - and encourages them to hold on to the same password for too long. The safest passwords are randomized, from a password manager

Eric's micro thoughts

