...attacker "knows" that a passphrase is being used, i.e. scenario b). In this case the password is already partlycompromised. It seems to me the 'normal' scenario is a) and that a carefully chosen passphrase, perhaps with uncommon...
http://www.schneier.com/blog/archives/2009/07/strong_web_pass.html