Regarding your last point, and as pure conjecture, it depends on how old the password is. When I was a student signing up for trial software etc. I often thought such things like "No one will ever guess 'offspring' as my password, that band is so obscure!"
It's also possible that he only used a simple password for sites that don't matter - like Adobe - but used a stronger password for his e-mail, bank, etc.
a) Don't have an email address with your real name in it.
b) Have several different active email addresses.
c) Never reuse passwords.
d) Only Use passwords that are a random string of alphanumeric characters.
e) Never use a hint that actually means anything.
I find it hard to believe that the real Snowden would use a single dictionary word as a password.