I see what you mean but even a random single or double digit being issued would be easy to remember and work round the security floor. Or username/pw like on blockchain.info.
If you look at blockchain info even with that security measure in place they've changed things (obviously out of a need as they've got bigger) so email & pw is no longer acceptable.
Actually, I worry about my wallet.dat files not because it can be stolen. It's not a problem, they are password encrypted. I afraid of software and hardware failure, so I try to regulary make backups, keep them in different hidden secret places and have all that usual mess everyone have with backups, you know

Brain wallet keep me out of this classic problems. So I can sleep good, deep and peacful, and disarm my MosinNagant

But, yes, my Nxt account passphrase is insanely long and complex, thanx to my l33t IT skillz
