The article is a bit miss leading. The so called security flaw does not reveal the e-mail address directly, but a MD5 hash of it. Sure it can be cracked, but it doesn't mean that it will get cracked.
And E-Mail-addresses aren't passwords; trying a few hundred variations for each firstname for each lastname is perfectly feasible and should crack a nice percentage of these hashes.