I wonder how many accounts have ever actually been compromised by a MITM reading passwords out of plaintext emails. I would guess it's very, very small.
That way, when their security is compromised, the attacker doesn't get your password.
Any site giving you your password is doing it wrong because they should never know it.
On top of that any takeover of a device like an ISP router or BGP misrouting is now an automatic compromise.