It's the 8-char password that I find absurd - that would take about 2 hours to brute force max.
This can be implemented in secure hardware (and without getting into attacks against that), you can make a password attempt, but can't modify the counter which tracks how many incorrect attempts have been made. Sufficient incorrect attempts will see the key material destroyed.
That drive claimed 128 bit AES, but they botched it.