Earlier quoted context omitted.
Anecdotally, most people I know without secure WIFI passwords pick things like: - Their address (sometimes with numerals spelled out) - Their last name - Their child's name - single (common) dictionary word - single (common) dictionary word + one or two digits.
for about 80% of protected home networks i’ve accessed the password ends up being someone in the home’s phone number.. not sure if it’s just because it’s often the only 8+ character string of numbers people readily have memorized or if it’s just lazy isp’s that set it that way (and lazy owners who never change it afterwards)..?
I'm sure it cuts down their support, but it usually means brute forcing only need worry about the last four digits.