Pretty much everything already has protection in terms of repeated logon attemps, typically the account will get locked out after a certain number of failed logins or whatever. This password strength concern is about what happens when someone gets hold of the encrypted password DB and starts trying to decrypt it.

