From the comments, it seems the passwords were hashed but they're (rightly) still concerned.
Unfortunately, there still seems to be some confusion about when/if the password reset has taken place, and whether users should change them now, wait for Dreamhost, or both (and then update them again after the reset!)
We're currently in the middle of resetting passwords, machine by machine. If your old password has stopped working, that means we've gotten to the machine that you're on, and you're safe to reset it through the panel.
Panel passwords are safe, BTW. The only passwords that we believe may have been compromised are UNIX user passwords (e.g, FTP/SFTP/SSH users).
Unfortunately, there still seems to be some confusion about when/if the password reset has taken place, and whether users should change them now, wait for Dreamhost, or both (and then update them again after the reset!)