@Kev@Mike@Kev
Not harsh at all, either your passwords aren't protecting anything important (in which case your post is irrelevant) or you passwords are protecting something important, in which case the password strength is critical to protection of the data you are responsible for (and ultimately your job).
>you have no idea what complexity arrangements are in place
You said 8-10 digit alphanumeric, sounds like you're defining complexity, this obviously excludes special characters, immediately you are revealing some of your complexity arrangements, futhermore in your second post you say "tempt them to reuse the first few characters of the password" this indicates that users are allowed partial re-use, again I can garner some more information about your security (which sounds poor).
User password education is important, but it's not that difficult, give a user the password d0-@Qr-+S1[/^!+vP and you're asking for trouble, but enforce at least one special charater, at least one digit, no position re-use, minimum of 9 you have a strong password, then tell the user how to use word association and phrase acronyms as tecniques to remember them, then they don't do stupid things, if they *have* to write down passwords then educate them to write down something which reminds them of a password, or partial passwords, if the users let you down, it's your poor education, not them, they are like children, take some responsibility man.
This is all by the by anyway, we were talking about the passwords you have to remember, where's your excuse? if you are an admin (like you imply) why are you using and allowing your users to use weak passwords? are aren't you enforcing stronger passwords? (if you're that sloppy I wonder if you even enforce a regular password change or change all your passwords when another admin leaves) hope you work for some noddy organisation that doesn't do anything important or has any external auditing otherwise that job that you haven't been fired from yet could become one that you have been.