Yeah, when I originally read about this I thought more or less the same thing. A low amount of entropy is already assumed in various attacks (like dictionary attacks), or even just guessing based on your knowledge of the person who created the password, it's the same deal. I don't see how you can assume the same thing for RSA keypairs though...