The vast majority of security leaks are from people writing their passwords down, or giving the secondary verification info to callers. Very few passwords are actually "cracked". Given this fact, it makes more sense from a security standpoint to have 3-character passwords with lockout on fail, rather than 8+ character passwords that will just get mined or social engineered. However, longer passwords do give the -appearance- of better security, so I suppose if this is more important than actual security, go with the longer password.