After seeing your original post here, I also asked for clarification, and received a similar reply from support:
The Lish password is set to a random string by default, however we would still recommend resetting this password even if you had not set one manually previously.
I had expected that if the password was not set, then password auth was disabled. I've told them that's what I want and have asked when it will be implemented.
I'm kind of upset they didn't clarify this in the initial email/blog entry. The way it was worded ("if applicable") implies that resetting the API might not be necessary in some cases. I think it is reasonable to assume that those who never generated an API key in the first place would've fallen under such a bucket.
Now it sounds like basically everyone should have reset their API key. Bleh.