I've seen (in cpanel at least, probably elsewhere but I cannot remember) , it warns you via a bar if the password is too weak.

But +1 for not allowing a member to choose a password that matches either their display name or login name (if using name logins)


I hate with a passion when a website decides for you what is strong/weak. I don't often have a problem with it what I use though.

Not allowing your name, username, and some other basic info items is one thing, but also consider the fact that that user is making that decision to be insecure. Inform them that "hey, this isn't a good choice" and let them chose to continue.

