I don't understand how the attacker got his hands on the MD5'd password? Does Open ID expose that data to anyone?
And Jeff used an insecure password on both the "evil site" and his Open ID provider.
The attacker only had access to Jeff's hash because he had access to a site that Jeff used.
I was expecting the answer to be that Jeff somehow revealed his real password publicly somewhere, not that this idiot stole it from a database that he had trusted access to.
This would be grounds for instant dismissal or even legal action in my book.