yea, you are now aware of the mass assignment bugs, but what about previously? even github got affected by it. are you saying that they are incompetent? what about bugs that have yet to be revealed?
what i am saying is that there may be some things that you forget about, because we are all humans. and in order to mitigate the risk from us being humans, we should not store passwords in a way that is easily recovered.
And again, I am not doubting your competence. What I am saying is that we are all humans. Google might have hired the best computer scientists around the world but they still got hacked. It might even be a problem with the programming language you are using (rmb mass assignment on ROR?)
"We offer people an off-site backup at the cost of trusting a third party with their password."
Yes, this is my main point. People have to learn that they shouldn't be giving out passwords to just about anybody.
and by storing the passwords, they are putting their users at risk. and we are in an era where email security means more than anything. it means access to all your services.
they should go think about how they can design a service securely before offering it.
what they could have done is to allow users to autoforward their emails over to their servers or something. not impossible, but i'm not their employee and i'm not responsible for thinking up business strategies for them.
in fact, seeing how your account was created to post that comment and seeing how it doesn't make sense, i would suspect that you actually work for them.
they can't, unless the email service gives them oauth.
and even then allowing a 3rd party to backup your emails is a very dangerous thing to do. they say that credit card is more dangerous, i say no. for credit cards you can claim fraud.
when your email gets hacked, potentially your whole digital life is gone
1) The app downloads your emails into their server.
2) Yes, they store that actual password. Which is ridiculous.
3) Yes, good for them for that, but still there are others where they store passwords. And that is not acceptable.
4) But that also means that they outsource the security part of things. Which doesn't lend faith to the idea that they know about security. And if someone realises how to control their application, all the passwords will be hacked.
5) Pidgin is stored locally. There's a difference. Not that I support it, but it's still better than someone storing my passwords.