Those are definitely the two 'take-aways'. If there is a hole here... there may be other holes that might be REAL security threats.
Other people are correct as well, in that the headline is link bait. I was expecting to find a way to get clear text passwords from my test OSX Lion setup. I can't actually do that on my test system, and I'd wager the vast majority of hackers can't pull that off either. At least not without changing the setup.
Of course... probably my fault for believing you could.
1. A vital piece of the operating system was compiled with debug flags intact. 2. Apple's lack of response on the issue.
I think this goes hand-in-hand with recent Kaspersky statement about Apple's poor security considerations.