> While many offer this, no one tracks them, and they can’t be limited to just the app (because, again, the protocols don’t work this way). So if your account gets compromised and you have 50 passwords, what do you do besides delete all 50 passwords and start over? Delete them one at a time and see how long it takes for spam to stop going out from your account? Reduce server security and log which password is being used (because that’s the only way to gain that insight from the universal protocols)?
1. Give the passwords names that identify the client app 2. Track that name / login / actions - it's not less secure to track browser type on the web, the equivalent is what's happening here (that's iPhone1, thunderbird on my mac, ...) 3. Present this information to the account user. I should have access to the logs of who's accessing my data. 4. If your account has 50 passwords, it has 50 clients that you have to delete and start over on. Same as if you'd used a single password on all 50 clients.