Eh, idiots will set idiotic passwords regardless of length. It's their own fault if they set it to something like that, not the admin's.
8 characters seems reasonable enough to me.
inb4 someone suggests we scrap passwords and use public keys instead
[insert witty quote here]