If passwords were hacked by brute-force then is the site providing unlimited login attempts and not blocking frequent failers? If that’s so then your password is practically no protection at all and they can all be guessed, weak or strong.
Don’t know. If there were a three try limit or something, and people were using crappy passwords, such as their username, then the script could just try the username as the password for each account. Might get 1% of accounts
If passwords were hacked by brute-force then is the site providing unlimited login attempts and not blocking frequent failers? If that’s so then your password is practically no protection at all and they can all be guessed, weak or strong.
The time to guess a password doubles as a password gets one character longer.