Well, I suppose you *could* resend the password in plain-text each time 
you log into a transport, rather than storing it on the server. That 
way a user with only read-acces to the filesystem on the server won't 
be able to steal it. But what kind of user on the server would have 
permission to read all files but not sniff network traffic? (maybe one 
used by a backup program or something). It might make things a little 
more secure one way (for example they won't end up in your backups 
either), but on the other way, sending your password in plaintext over 
the wire isn't that secure either. So you'd have to use SSL, wich can 
be a bit heavy on the server and only works if the link between the 
server and the transport isn't vonurable either. 

