I did this with a site of mine a couple years ago, and it worked great.
BUT -- because of the site's nature, 1) a hacked/compromised account would have been a minor annoyance at worst, and 2) users weren't expected to log on more than once every month or so.
I think it depends very much on your site's profile.
BUT -- because of the site's nature, 1) a hacked/compromised account would have been a minor annoyance at worst, and 2) users weren't expected to log on more than once every month or so.
I think it depends very much on your site's profile.