I agree the little chuckle is pretty dumb, but it points to an important discussion for technology people: how do we do AAA in a way that actually works? OpenID and Facebook Connect seem like good steps to me, but we're not there yet. So many web apps totally ignore AAA and just throw some pre-packaged solution with it's super-amazing-secure 256-bit salted hash and walk away. There's opportunity for innovation in this space. The bash.org quote is just to get the discussion started and highlight the pathetic state of things.