They've had some pretty horrible mistakes with respect to security though (before Andreas' time though, so no reflection on him), and the basic model of a web wallet is inherently broken...
however as you suggest, on the server side, I would expect them to use a much higher 10k or so round count.
These sound like mistakes that many beginner companies can easily make when trying to craft them. Why is there a demand for perfection out of the gate? And why are offers to remedy the situation not given the same kudos?
Because it only takes one flaw for money to be permanently lost.