Mullenweg countered with the fact that all Web applications must either store their database credentials in plain text or keep a plaintext decryption key around somewhere.
In addition, you should consider avoiding plaintext-password network services: The POP3, FTP, and Telnet daemons pose a special risk because their passwords pass unencrypted across the open network, sniffable by any nearby machine along the way.