Actually I use extremely long passwords for anything financially sensitive.
Did I say make passwords short, did I say base them on a real word, no I didn't, did i I say I use a password manager, well yes I did.
I'm pretty sure some brute force algorithms use dictionaries, and possibly try well...