Earlier quoted context omitted.
It appears a lot of people have already warned Schwab about this. Sadly, I expect it will change only if there was some embarrassing large scale attack that is subsequently publicized.
How would such large scale attack be perpetrated? The worst you could do would be to lock out a lot of accounts.
If someone stole a database from a provider that implements passwords correctly, the best they could do is get some low-hanging fruit passwords.