I mentioned this to Fran elsewhere, but it'd be nice to see a password blacklist that would not allow clients to utilize easy passwords to bruteforce.
Things like: root, password, passw0rd, password123, server, etc should not be allowed.
You could even go a bit further to ensure clients use...