I used to work at a place that set passwords. They would cook up good pws, but then email them in the same message with the user name to the users. They thought I was weird because I refused to do that. I would email the user name and then phone with the pw, or visit personally, or some combination like that.
They had it set so that if you failed three times with your login, it would lock you out. I wanted it to be ten times because a LOT of folks miss it three times, but a pw cracking program would try 1,000 times in a couple seconds. They didn't understand my logic.
I think that now-a-days, the best pw would be two or three characters long. Nobody would expect or try that.