Verified that I was able to create an account with 'password' as the password. Perhaps a password meter and a basic set of rules to disallow extremely easy passwords.
Agreed. In the area of security, NodeBB still has a ways to go, but the project is still young, so there's room and time for adding features like that.
At some point I'm going to want to implement 2-step verification as well. I hope someone else get's a system for that working before I fail at attempting it.