Except that storing the passwords in encrypted form in a keychain is explicitly meant to shield them from prying eyes even in the event the hardware falls in the wrong hands. You may get at the file, you just can't get at the data.
At least - that is what I as a user would want and expect. And from a technical point of view, that situation can be achieved with modern crypto. Clearly, the way Apple implemented it is not sufficient in this regard. That is the news.