If the password is not the kind of thing an idiot would have on his luggage, it is often derived from the user's home address, birthday, favorite athlete's jersey number, anniversary, or other things that could be predicted through social engineering.