No one here is saying that users shouldn't have better password policies. They should.
What is being said is that having a devil-may-care attitude toward safe guarding your users account data is not ok.
If you use your bank password for anything other than your bank, you're clearly not taking security seriously.
If you think you shouldn't have to properly secure user account information, you're clearly not taking security seriously.
Both parties can be wrong, but that doesn't excuse either side.