You're repeating yourself now, do remember that all systems are built by humans, and as far as encryption goes do remember that unless your email is encrypted on the server using a password requested from you in order to encrypt and decrypt it every time you read it, then you are not safe. We are professionals offering a professional service. And FYI, Rails developers have been aware of mass assignment bugs a long time before github got bitten.
I fail to see the point made by that commenter that has not been made yet in this thread, other than the funny accusation of malice. We don't store plaintext passwords, and we are very aware of mass assignment bugs. (being suspected of such naive practices is why I mentioned the incompetence thing earlier). If security is a chain, then we strive not to be the weakest link. People have to learn what's the risk involved in giving out their password, how to evaluate who they give it to, and then make their own choice regarding whether they want to give it away or not. I get my hopes high when I read that you wouldn't mind people giving their password to a company that is better than 'just about anybody'. Convincing people that we are trustworthy was a big initial challenge for us, and still is as we reach out to more and more users.
Indeed, no system is fully secure, and we don't try to hide that fact, that's one of the reasons Dropmyemail exists in the first place. We offer people an off-site backup at the cost of trusting a third party with their password. This is a risk assessment discussion, and I believe although good for raising awareness about what dropmyemail offers, the original articles fails to make a distinction between the objective information it provides and what are your personal valuations on the risk involved (for example, it assumes one of the worst possible scenarios regarding our competence). Things get a bit confusing when non security related topics like storage capacity are mixed in though. I believe you are trying to help people to be safe and choose the better tool to solve their problem, I do think you are underestimating them a bit, but in case I'm wrong I repeat how valuable your article is in raising this issues.
I do believe that all this kurfuffle originates from a 'false package deal' composed by: factual data (we store passwords), your assumptions about our incompetence (we're bound to lose them), and your subjective valuation of risk vs. convenience. You should not feel bad about other people breaking down the argument in the different topics. I am a Dropmyemail employee who works hands on with the security of the site, although I'm replying on my personal capacity. We don't practice security through obscurity so we can discuss the technicalities of our security measures here. I would appreciate not being treated as an incompetent goon though, to keep things friendlier. I see on this thread you accuse someone of being sent by the company I work for to discredit you personally: They did not, furthermore, I personally see your article as a valuable service, you will see in our site that we try to be as transparent as possible, and there's nothing that I could want more than for people to actually know and understand what Dropmyemail is about. Thanks for your article.