Earlier quoted context omitted.
This. For more information on why this is the case, here's a pretty good article on it. http://arstechnica.com/security/2012/08/passwords-under-assa... The simplified version: Every time a password is cracked it is added to a database of hashes used to hack other databases. Essentially crowdsourced cracking.
That only works on broken sites that don't salt.
http://www.theregister.co.uk/2012/06/07/linkedin_admits_data...