> It's stronger than using an external service or a software
How do you figure? Your scheme clearly has less entropy than a randomly generated string of the same length, and if an attacker learn two of your passwords, then they know they only have four characters to brute force for every other password you possess.
How do you figure? Your scheme clearly has less entropy than a randomly generated string of the same length, and if an attacker learn two of your passwords, then they know they only have four characters to brute force for every other password you possess.