Seems like the author is implying but not directly saying the hashed passwords were not salted. Am I reading that right, and does anyone know if they were salted?
However, if your password is "password" or another very common password, then someone can just try those with the embedded salt and still find out that was your password.