No matter how they decided to store the password, if somebody has root access to the device, they can find a way to read it. If they can't find a way, the phone won't either, so it won't be able to log you in.
The only answer is to not let your device store your password. Choose security or convenience, but don't expect both.
(This is no different than Pidgin storing your passwords in plaintext[1] with the exact same reasons and consequences.)