I think that a lot of the problems that are inherent to passwords might be mitigated by not allowing the user to choose a password. A strong, randomly generated password being given to the user and changed periodically would almost force the user to use some sort of password manager. If this were adopted industry-wide (a big ask, I know) then users would be able to use the familiar "enter username and password" syste…
> A strong, randomly generated password being given to the user and changed periodically would almost force the user to use some sort of password manager. or it would force them to click "reset my password" every time they use your service. now your service is only as secure as their email account.
Surely that was already true?