I wonder if the researchers realize that people sometimes intentionally maintain weak password, since they are easy to remember and it's an acceptable risk for the account to get compromised.
For example, if my Gawker commenting password is 'hello1234', and it gets compromised, what's the worst that can happen? My Gawker commenting account turns into a spam feed? Oh noes my life is over!! </s>
For some applications, weak passwords are perfectly acceptable.