short passwords are still a security weakness even when properly stored because the time necessary to brute force them is relatively low.
(Then again, the implementations I see are mostly from well-known projects or customers that care enough about security to hire us. It's biased, but I do think word has gotten round about hashing and salting.)