Ok... 10,000^4 * 10 = 100,000,000,000,000,000 @1,000,000,000,000 passes per second (nsa level bruting) = 27 hours to break one single password. There's far more low hanging fruit in an encrypted list of passwords than to bother with random common word combos. Unless you're a specific target, it's not lucrative to a hacker to use brute forcing to get through the last 10 or 20% of users with good passwords.