You know how a spell-checker trained on English already understands that 'q' is almost always followed by 'u'? It doesn't need to relearn this from scratch for every new document. PassGPT+ applies the same insight to passwords: humans don't generate random strings, they generate strings shaped by language — fragments of words, predictable substitutions, keyboard patterns. A model that already knows English should have a head start on guessing your password. This paper proves it does. The committed claim: taking GPT-2's pre-trained linguistic knowledge and fine-tuning it on leaked password corpora with character-level tokenization recovers 22.53% of held-out RockYou passwords at 10^8 guesses — a 16% relative improvement over PassGPT, which trains from scratch on passwords alone. That's not a marginal gain. It means the structure of natural language encodes real, exploitable regularities in how humans choose secrets. The transfer experiment is the sharper result: when moved without retraining to a disjoint 2020 leak dataset, PassGPT+ retains 79% of its match rate. Linguistic priors aren't just memorizing one corpus's quirks — they capture something persistent about human password generation across years and populations. The architecture is straightforward: GPT-2 (autoregressive transformer, ~117M parameters in the small variant) with a custom character-aware tokenizer replacing the default BPE vocabulary. This is the key engineering decision — standard GPT-2 tokenization chunks text into subwords optimized for natural language, but passwords need character-level granularity because a single character flip changes everything. The fine-tuning uses the RockYou corpus, a well-established benchmark in password security research. The method sits squarely in the autoregressive language model family, betting that next-character prediction is the right inductive bias for passwords. Alongside PassGPT+, the authors introduce PassDiffusion — the first absorbing-state discrete diffusion model applied to password generation. This is the genuinely novel architectural probe: diffusion models have dominated image generation and are making inroads in text, so testing them on passwords is a natural question. The answer is emphatic and negative. PassDiffusion underperforms by two to three orders of magnitude. The paper's explanation is structural: passwords require exact-match generation of discrete sequences, and iterative denoising is poorly matched to this constraint compared to left-to-right autoregressive prediction. This negative result is arguably as informative as the positive one — it draws a clear boundary around where diffusion models struggle. The integrity picture is reasonable but bounded. The RockYou benchmark is the standard community dataset for password research, which is good for comparability but also means the field has been optimizing against it for over a decade. The transfer test to a 2020 leak partially addresses overfitting concerns, but both datasets are from English-dominated contexts. The comparison baseline is PassGPT (the direct predecessor) and PassGAN, both named with numbers. Code is released on GitHub. What's missing: no comparison against the strongest rule-based tools like hashcat with optimized rulesets or PCFG-based generators, which remain the operational gold standard in real password cracking. The paper is measuring generative model against generative model, not generative model against the best available attack tool. The milestone question for this line of work is whether language-model-based password generators can match or exceed the coverage of optimized rule-based crackers (hashcat, John the Ripper with community rules) at equivalent guess budgets. That comparison would move this from an academic exercise to a practical tool. The gap is probably 1-2 papers away — someone needs to run the head-to-head on modern leak datasets at 10^9 to 10^12 guess scales. The obvious experiment not run here is exactly that: a direct comparison against hashcat or PCFG generators on the same benchmarks. The authors likely either lacked the operational setup or are reserving it for a follow-up paper focused on practical attack simulation rather than the linguistic-prior thesis. The broader significance is conceptual more than operational. PassGPT+ demonstrates that password security research should treat passwords as a dialect of natural language, not as an independent distribution. This reframes defensive strength estimation: if pre-trained language models transfer this well, password policies that merely enforce complexity (length, special characters) without breaking linguistic structure are fighting the wrong battle. The 79% transfer rate across a decade of password evolution is the number that should make security engineers uncomfortable.