What? If someone has full access to BTT server, they can probably access the messages, password length wouldn't do anything, as I doubt the text on the server is encrypted by user's password.
And that "50+ char" password things is total nonsense. People just make up these numbers out of thin air. elliptic curve cryptography (used by bitcoin and nxt and all other cryptos) can be cracked in 128-bits operations -- that is equal to about 22 char random password.
WHAT?
Pliiz use consistent vocabulary, not char, bit, word ... oh, you edited the post

What means "password length wouldn't do anything, as...the text...is encrypted by...password" ?
u r saying 50 chars long password is not safe.
How do you validate that?
The hacker must still try all the possible passwords with length 8, 9, 10, 11, ......... 50, 51, ....
How long does it take to try those for ONE account ?