It will recover all windows passwords for all accounts in about 3 - 5 minutes.
Because of the sizable investment in computing processing, Rainbow tables beyond fourteen places in length are not yet common. So, choosing a password that is longer than fourteen characters or that contains non-alphanumeric symbols may force an attacker to resort to brute-force methods.
I've been using a 15 character password for ages, and I have this thing for non-alphanumeric characters.

I should really set up a 127 character password for XP, though...