They are correct in their assertion, presuming an untrust worthy service provider. If I were them I would not allow my security to rely on the skill or goodwill of others.
It would be best practice. Especially if you are effectively only using it as a password i.e. single factor authentication.
The danger is that a site you are logging in to will reuse your login details to access another site you might also use. Effectively your classic man in the middle attack.