A "strong" password rejected by the site as too weak.
- Why:
- Composition rules check for character classes, not entropy. A site can demand a symbol and a digit while happily accepting Passw0rd! — which is among the first few thousand guesses any real attack makes.
- Fix:
- Satisfy the rule, but choose length for actual strength. Anything above 80 bits of entropy is beyond brute force with current hardware.