Yes, this is also explained in a link from our About page here: http://plaintextoffenders.com/post/7006690494/whats-so-wrong...
TL;DR - it's still a security issue (albeit smaller), we've included it in our mandate, please don't do it.
TL;DR - it's still a security issue (albeit smaller), we've included it in our mandate, please don't do it.
Only if you're dumb enough to not delete any password emails.
Granted, preferable any site sending you your password in an email should either send a reset link or "your password is 'red*'"
You delete it from your MUA, but how can you be sure that it wasn't stored in any of the intermediate servers?