This is a really bad article. I would call it nothing less than fear-mongering. Let's say they decided to encrypt the file. They would have to store that key in plain-text somewhere. Of course, they could encrypt that, but then that key would have to be stored somewhere. No matter how they decided to store the password, if somebody has root access to the device, they can find a way to read it. If they can't find a wa…
It is bad either way. The phone should keep an access token (which can be revoked), not store the user's password.
So are you going to phone Apple and ask them to change their website/ITMS/iCloud/DeveloperCenter password/authentication system? No? Neither am I.
Samsung storing the passwords in cleartext is lazy, but if the assumption is "you can only read that cleartext file if you've got root", since a consequence of having root means you can intercept anything the user does anyway, it's _maybe_ an excusable decision. I'm quite surprised they didn't choose to use a passwordsafe/keypass/lastpass/1Password style encrypted storage format though. It's not exactly rocket surgery…
(I wonder how that file appears on backups though? Does Android by-default encrypt backups? I know iPhone _can_ encrypt them, but doesn't by default. This file could be quite dangerous if it's sitting on a lot of people's laptops/desktops unencrypted...)