Regular reminder that new users in general don't care at all about the security of your site.
Most of your signups are not going to generate and store a secure password "just to try you out", as evidenced by the most common password here "123456". If you force people to signup to try your site/app, many (most?) of them are going to use a crap password. If you're _lucky_ that'll be 123456, and not their email/facebook/internet-banking password.
The answer isn't to try and force "good passwords" from users who don't care. Remember, by definition - they don't care.
We need to start trying to not require users to come up with passwords until they do care. Maybe just cookie me and let me tromp around as an unauthenticated user until I do something that needs me to set up a password-protected account. Maybe ask for my email and send me a login link that hooks me into my account/data without me setting a password (lets face it, your password security is going to fundamentally rely on the security of my email account, 'cause your "forgot password" story says you'll happily send a password rest link there, right?
I know Start-up-de-jour desperately needs "signed up user numbers" for their investor pitch, but that's not going to motivate me to stop using 123456 or password123 as a password when startupdejour.io demands I create an account just to look around.