Regular reminder that new users in general don't care at all about the security of your site. Most of your signups are not going to generate and store a secure password "just to try you out", as evidenced by the most common password here "123456". If you force people to signup to try your site/app, many (most?) of them are going to use a crap password. If you're _lucky_ that'll be 123456, and not their email/facebook…
why should users care ? what makes you think it's our job to make them care, we built another shitty system, it's not the users fault, asking them repeatedly to do something proven by cognitive science to be very challenging for most is just dumbness incarnate....
So why are we pretending they do - and requiring them to give us email addresses and set up secure passwords?
(Especially when the "upgrade password storage to something more secure than plain text or MD5" is constantly being deprioritised below "add features X, Y, and Z that the product owner claims our next three investors on our pitch schedule have Tweeted about in the last month"... "We'll 100% definitely get to it once Series A comes in. for sure! Except perhaps for the 7 million 'legacy users' we signed up with plaintext passwords during our growth hacking private investor and seed round stages...")