Private keys should have over 128 bits of entropy, which is enough to make it un-brute-forceable with at least the amount of energy likely to be obtained by any human organization on earth. http://en.wikipedia.org/wiki/Brute-force_attack#Theoretical_... That's what makes it un-guessable. Also, some users do choose passwords with at least as much entropy and are also unguessable. But most don't.