Not sure how I feel about the comparison to the shadow passwords file -- the shadow file doesn't contain the raw password, but a hashed version.
If someone steals the shadow password file, they still have quite a bit of computation to do to crack the credential.