Andreas is the CSO of Blockchain.info, a site which takes client security seriously enough that they never touch their client's private keys, rather than "handing out IOUs to their users"; maybe we'll see a rise in adoption of this approach.
however as you suggest, on the server side, I would expect them to use a much higher 10k or so round count.
These sound like mistakes that many beginner companies can easily make when trying to craft them. Why is there a demand for perfection out of the gate? And why are offers to remedy the situation not given the same kudos?
Because it only takes one flaw for money to be permanently lost.