I think another good question is, while it's clear that their extent of password security is terribad and needs to change, what is the real likelihood that you're going to get hacked? People would have to have your cell phone number AND know that you're a VM user. Is it possible to extract carrier from cell phone number?
I'm not defending the situation, but the real chance of brute-forcing an account is dependent on knowing the specific cell phone number = and knowing that it's a VM account. Think about myself, the only people I can think of who know that much about my cell phone are probably just my friends and family--I doubt they're going to try to brute force into my account.
Regardless, it should be fixed--I wonder if a petition is going to start up? Also, is there a stipulation of site access security that the FCC presides over? Can one lodge a complain on these grounds?