This is one of the reasons why I have different Apple ID for app purchases (with weaker password which I'm more comfortable to type over and over again when purchasing apps) and different for iCloud (which I need to type only once, configuring the device).
I saw many people buying their apps in public and the password input in iOS isn't really secure from bystanders. As a Gizmodo reporter he probably went to dozens of events where he was pitched to try someone's app and maybe even given App Store codes. If he used to download apps on such events that might be the source of his leaked password. Someone could simply see what password is he typing.
As long as Apple requires you to type the password with each purchase, it is wise to separate your sensitive data/services with the App Store credentials.
If you get the chance to watch a kid playing with an iPhone it's an eye opener. The 15min no auth required again window after an app purchase is the devil's time.
I saw many people buying their apps in public and the password input in iOS isn't really secure from bystanders. As a Gizmodo reporter he probably went to dozens of events where he was pitched to try someone's app and maybe even given App Store codes. If he used to download apps on such events that might be the source of his leaked password. Someone could simply see what password is he typing.
As long as Apple requires you to type the password with each purchase, it is wise to separate your sensitive data/services with the App Store credentials.