I always wonder about how easy that would be to spoof, because it seems like it'd be trivial.

...but obtaining that phrase may be nontrivial.

Sorry, I mean the current implementation seems trivial to spoof. I agree that doing something like your suggestion would make me feel much more comfortable about those logins.