Didn't the breach disclosure say "most" passwords were hashed with bcrypt? Obviously I don't know what everyone else got, but it can't have been better or they'd have said so...
I don't mean to detract from your point, good prevention beats reactionary resets. It just raised my eyebrows at the time as a strange weasel word in a claim that users were safe.
Now that you mention it, I remember that too. Seems weird, I don't know why you'd have some passwords hashed in other ways. Even if you've migrated, why not migrate everyone at once?
Sure, and even if the passwords stay secure this is bad for users.
But I'm specifically reacting to "hashed passwords (the vast majority with bcrypt)". That's the sort of thing that's usually code for "except the ones which are horribly secured and will be compromised in a week".
I don't mean to detract from your point, good prevention beats reactionary resets. It just raised my eyebrows at the time as a strange weasel word in a claim that users were safe.