As is the policy/decision making that results in logs having the passwords - you can still have very locked down database access. Logs tend to get spread around all sorts of systems, and access control for logs is almost ALWAYS lower than DB keys. They're also cached for search-ability on any number of elasticsearch or business intelligence platforms, so getting rid of them after the fact is even harder. At the very least its an equivalent problem.