I would say the problem is that there are a finite number of words which folks usually choose from when using diceware.
That way, with enough computing power, the chances of it being cracked are much bigger.
With normal websites though, the service usually blocks you for a set amount of time after multiple failed login attempts, so bruteforcing all possible diceware combinations is much less likely to happen.