For .htaccess passwords, they are usually 32-40 characters long. Though because I know my computer is secure (encrypted disks, ethernet connection, biometric access, in a room with 24 hour alarm system including motion and entry sensors), I let my browser remember them. On a wireless connection, I wouldn't do that.
Then to actually login to an Admin CP, it would be a more sensible password. Current one is 12 characters with digits and letters including upper and lower case. Don't usually use punctuation in a password. Thinking of putting Admin CP on a new site under SSL with a self-signed 128-bit certificate. No need for a commercial one since it is just for private use.