So, a guy that knows how to write an app, or inject his malicious code into some other app, and convince you to download and install it, will have more trouble getting your obfuscated passwords than those written in plain text? Come on...