I think it's becoming more and more common for the PSK to come on a sticker from the all-in-one router/modem your ISP sends you. So, the user never sets a passphrase, never sees the control panel, and has the key ready to hand out by just looking at their "internet box." This attack is perfect for that.
If manufacturers stopped using fixed length keys for a particular product line and made use of the entire alphabet it would make this kind of exercise infeasible.
I'm not sure how many people know about the WPS button most routers have now, but I've got several people using it. It's rather slick when it works (I've only had it fail on HP printers). Windows 8 actually tells them to press the button. I think Android could make this more blatant to spread adoption.
You select the network on your device and press the WPS button and a few seconds later it's synced. Never need the password again.
It seems like this should be easy to defend against, but everything I've ever read about WPS says no one seems to be putting any such protections in place.
http://en.wikipedia.org/wiki/Wi-Fi_Protected_Setup#Brute-for...
Not only that, but routers verify the first and second halves of the PIN separately. So instead of brute forcing in a keyspace of 10000000, you only need to find one number up to 10000, and a second number up to 1000. (The second half of the PIN is actually a 4-digit number as well, but the last digit is just a checksum digit.)
If it weren't for that issue, attacks would take months/years instead of minutes/hours.
Random comment I read somewhere, so may not be reliable.