Does Pidgin still store passwords in a plaintext file in your user profile?
The same is ultimately true for browser password managers also. Do you know both Chrome and Firefox let you export all your passwords as plaintext CSV?
If the drive is not encrypted, surely for Windows at least it's possible to reverse engineer the encryption secret. Maybe on Mac you could do something with T2, but now your config is not portable, and still doesn't solve the malware on the system case or the "your sibling/visitor/housemate whoever has physical access".
[1]: https://web.archive.org/web/20200830203837/https://docs.micr...
Yes, that's how git does it.