Earlier quoted context omitted.
> At what point would they exhaust their bruteforce capability or decide that they've probably got the wrong pattern and go for another one? Go in increasing order of difficulty. Or estimated rarity based off of password dumps. Something like: One character, two characters, one word, one word plus a character, one character plus a word, one modified word, three characters, etc. "word" being a list of most common word…
> That would just be "four words plus five random characters". Aye.. if you were going to pick the simplest (most bruteforceable) pattern first, you wouldn't want five random characters now, would you? I thought that's the whole point of this exercise :-) Of course I could decide to repeat that bit pattern four times and that adds no entropy if the pattern is assumed to be fixed, but then we get back to having the at…
Don't try to outsmart the person cracking the password. Assume whatever clever scheme you come up with is relatively common. If only 0.05% of passwords use it, that's still less entropy than adding two more characters. And it's a lot safer to underestimate than overestimate.