With the previous demo, if a user’s Password was shorter than their Secret, we repeated the password’s characters until we had enough to pair with the characters in their Secret.
For long secrets, the password could be repeated many times, creating patterns which when paired with the predictability of human behavior, opens up an enormous vulnerability.