Why aren't security experts and hackers mixing and matching the characters that make up the password? I.e. instead of super!!!think3rs, try Supr3Think0rz. Is the added required processing too large of a trade off?
I don't know what the best practices are, but some crackers definitely do do that. And yes, the added processing is generally too large for non-cracking applications.