Additionally, that was a flaw from a year ago. Still incredibly stupid, but not really relevant to the recent hacks at all. This is being used to discredit the fact that investigators are pointing to "a" state actor for the source of these hacks.
I'd argue that it's very relevant; if they were making such terrible decisions a year ago, what else did they do wrong between then and the hack? I am reluctant to assume that they didn't make other mistakes, given how obvious this password flub was.