Unfortunately, enforcing strong passwords drastically discourages new user signups. I remember when the security team enforced stricter password policies at Dropbox new signups dropped by a factor of 10 (by "stricter" I don't just mean length + special chars, they experimented with banning all of the 100K most common passwords). It just isn't economically sustainable to enforce strong passwords.