That's true. You'd have to brute force it. However, brute forcers only work for a small percent of the user base. As in, like 5%, which is why it's generally used when you have a LARGE list of users, not a single user.
On top of that, Gaia now uses Captcha's and max login attempts to prevent brute forcers. So there is no sure-fire, or even remotely likely, way of doing it.