Querki should prevent users from using excessively-common passwords
Summary: Nothing too radical here: we should find a good list of the most common, say, thousand passwords, and simply forbid those when you sign up or change your password.
There should be clear UI guidance attached to this, saying that these passwords are so common that they are very easy for someone to guess and break into your account.