This guy only used 302 from a dump of 453,491 passwords to come to these conclusions. I can imagine no reason why he'd intentionally invalidate his analysis by using such a low sample size unless this conclusion doesn't actually hold when you use a significant sample. I am highly skeptical.