Indeed, agreed. Limiting the number of tries would be a better way, also emailing the user & admin of failed attempts (including the IP, if a cookie or session identifies them as anyone) and also email the user when the correct answer is given and the password is changed. Just a few thoughts