Those are rough estimation and actual time to brute-force the password depends on algorithm used for encryption (encryption require more computational power compared with hashing) and hardware owned by the hacker.
Sure, rough. In confidence, using the rainbow tables (which are flooding the Web) it can be achieved even faster and it doesn't require too modern equipment. Those estimates simply show the password with eight characters all together is too weak.