Do I understand correctly - it's the same reason why browsers keep plain text passwords locally when the users selects to save them?
[0] https://security.stackexchange.com/questions/170481/how-secu...
[0] https://security.stackexchange.com/questions/170481/how-secu...
In this case, anyone can access that registry and get the pwd.