This is why I just tell people my can password in general chat, to save them all the bother of hacking...
Here are some of my favorites;
1111 or 1110 , that 0 is a killer
2011 a fine fine year
day and month or month day .... 2804, 0428 Both super secure, no hacker's here
which ever easy to remember code you use, just be sure to never change it, and for large corps, everyone should always use the corporate standard 0000 - no deviation is permitted.
( jk - don't do any of the above )
Flagging isn't a great deterrent. Following your 'greifing' model, said greifer can sit in an arkhe until they crack the code, and either delete everything or just have a sequar in tow.
There's been a few times when I've had someone click my can, and adding a 10 guess and flag isn't a terrible idea, it's just so uncommon that the potential for abusing the flagging mechanism is going to be used more than it would be as a deterent.
How about 5 times and you just blow up, with no aoe of course, or get teleported to a random interior beta tp