> "can't effectively be bruteforced like a user+password."

Only when the password is weak enough to bruteforce swiftly. It will take literally thousands of years to bruteforce strong passwords.

But you only need one weak password to get in

But you only need one password to protect your HTTP auth phpMyAdmin so just make it 30 characters.