A sensible password-selection policy really only has two principles:
1. It shouldn't be in a dictionary, so that the only option is brute force 2. It should be very hard to brute force
#1 means "don't use anything in this guy's list."
For #2, the concept of "password haystacks" is useful: