One approach you might try is on every test run, randomly select some lines
from the list of common passwords and verify they fail the validator. That
way we know it's not just testing a single, fixed, contrived case.

