The only "really bad idea" for passwords is password reuse. A unique 14 character three word password for each site you use will protect you from the threats you face online.
The fact that someone can relatively quickly crack your password if you used 3 random words is meaningless. That only works if they knew that you did that in the first place. Capitalize one random letter in all of that, throw a number between the second or third letter, add dashes, whatever and they're totally screwed. Game over, you win.