Interesting idea, kinda like the second step security they have for LogMeIn when accessing a remote computer.... Login using regular password then have them enter a part of a secondary password (e.g. password) and have them enter the letters for the blanks (e.g. **_**_*_)