That and allowing anyone access to your computer's graphical interface as if they were at your computer, even yourself over a web connection, is a bad idea.
I think the 8 character limitation is helpful. Because if you need to protect yourself against it, you can ask "but wtf do I really want to do? Probably not a VNC server..."
I reported a software bug in a commercial package (Allegorithmic Substance Designe) a few months ago. The support guy told me that, to help me, he wanted me to install a VNC server, send him my id and password, and let him have access to my machine so he could debug the problem.
When I balked he acted all offended and told me they work with some of the biggest companies in the industry, they see lots of stuff on customer's machines, and are totally trustworthy.
I think the 8 character limitation is helpful. Because if you need to protect yourself against it, you can ask "but wtf do I really want to do? Probably not a VNC server..."