@Lazeez Jiddan (Webmaster)
No silly requirement like must have one capital letter and a number and a symbol.
Glad to hear it. I have watched with child-like wonder as the "secure password" myth has grown and grown over the decades.
Anyone with any systems experience, like yourself, knows that the secret to foiling brute force and dictionary attacks is to put a meaningful temporal limit on attempts, keyed to the user name and the source address. This approach makes even 6 alphanumeric characters impossible to break in any useful time frame.
Stupid passwords are impossible to protect against without two-factor implementations, but then stupid passwords belong to stupid people who, perhaps, should get what they deserve.
Key logging attacks are very rare, but when done are again only securable by two factor.
I have yet to see any reasonable justification for the current fad of mandatory mixed characters, cases and symbols. In fact such fancy passwording usually reduces security, because the average poor user has to write them down somewhere to remember them, given most users these days use dozens of passwords.
Thank His Noodliness that mandatory periodic password changing has fallen out of favour.