@BenAveling The positions are specified by the prompt, the customer chooses the word. The word not being chosen randomly matters a lot.
Sure, an attacker can't get into every account, but if they phish 100 people, they'll probably be able to get into most of them.