aside from mac os which has an encrypted keychain, how do you expect a password to be stored that is used by open source software, which has to be accessible by software that cannot prompt the user for a password?
I must say I don't agree with the Pidgin devs. They think that the user will use the software in a more secure manner because they assume he's aware that the password is stored in cleartext.
That may be true on 1% of the cases. But the other 99% of the people probably don't have a clue, and they wouldn't even know where to find the accounts.xml file in the first place.
I mean, mail clients such as Thunderbird can be set up to safely remember passwords without storing them in cleartext, right? So clearly it's feasible...
otherwise, set a master password to encrypt the sqlite database and then make the password timeout after a short while: https://addons.mozilla.org/en-US/firefox/addon/master-passwo...