I should have said for example rainbow tables, thats just one method. My point is that it doesn't take forever to crack passwords now, yes a longer or more complex password will make it take longer to some extent but don't rely on it to make that much of a difference.

Interesting to add that there is now 4 factor authentication.
1. Something you know - password, pin
2. Something you have - smartcard, token
3. Something you are - biometrics
4. Somewhere you are - location based.