This seems reasonable to me. Key loggers on users' computers are probably their most common breach vector (by far), so whatever password policy minimizes that risk is probably best. You also see this in their other security policies - for example, asking a secondary password (security question) which sets a long-expiration cookie. With 128-bit SSL on the login page and a 5-guess lockout policy, there isn't much reason for strong passwords.
Comments
This seems reasonable to me. Key loggers on users' computers are probably their most common breach vector (by far), so whatever password policy minimizes that risk is probably best. You also see this in their other security policies - for example, asking a secondary password (security question) which sets a long-expiration cookie. With 128-bit SSL on the login page and a 5-guess lockout policy, there isn't much reason for strong passwords.
Damn text. So hard to get sarcasm sometimes. It was, right?
Considering that andreyf posted original link -- yes, it was a sarcasm :-)