The ChoosePassword view has a password validation routine that attempts to enforce a certain degree of password strength, yet currently “abc123!” and “passw0rd!” will receive high strength scores. Since the password is used with browser-passworder to protect wallet keys, it’s likely that it’s worth brute forcing.