• letting them configure a second password that would be a minor variation of the first – maybe one letter switched from lower to upper case

    I can't imagine what could pOssibly go wrong.