If you do enable SMTP/IMAP: sure, it's correct. But that often doesn't apply, so I don't think it's a "trick" or "sleight of hand".
> While many offer this, no one tracks them, and they can’t be limited to just the app (because, again, the protocols don’t work this way). So if your account gets compromised and you have 50 passwords, what do you do besides delete all 50 passwords and start over? Delete them one at a time and see how long it takes for spam to stop going out from your account? Reduce server security and log which password is being used (because that’s the only way to gain that insight from the universal protocols)?
1. Give the passwords names that identify the client app 2. Track that name / login / actions - it's not less secure to track browser type on the web, the equivalent is what's happening here (that's iPhone1, thunderbird on my mac, ...) 3. Present this information to the account user. I should have access to the logs of who's accessing my data. 4. If your account has 50 passwords, it has 50 clients that you have to delete and start over on. Same as if you'd used a single password on all 50 clients.
Then again I'm not a software developer, I'm an admin and hope to be hiring a dev this year. MXroute works mostly on open source or licensed software, with a heavy focus on custom in-house configuration being around the outbound relays, as the initial focus of MXroute was based on getting emails to their recipients, no matter the cost. These days, that's increasingly difficult and time consuming for a lot of people (IP reputation, etc).
SELECT username, ... FROM applications WHERE username = ? AND password = MD5(?)
to SELECT username + ' ' + applicationName FROM ... (as above)
Then log the user name for each session, or return an extra field that is the app name when doing a password check (assumes your MX can do this). This is the general idea, and it's more pointing out why the advice is wrong, than talking about how to fix it and make it possible.