Well, they hacked your password file. Not theirs, didn't they? So in the end it's your (or your server admin's) job to secure the server.
You can't blame them if something goes wrong on your end and they do not provide the tools to fix it within seconds.
|