We might want to consider adding some type of JavaScript strong password widget for use when someone creates a new password (account creation or resetting the password). Here's a nice one, as an example of something that can possibly easily be dropped into the system.... http://www.egrappler.com/jquery-strong-password-plugin-power-pwchecker/