yea thats exactly it... but it is actually related to itself unlike chocolate gangrene and amputation, you are no longer my hero
The argument is "gaining access to peoples accounts is possible if someone has access to the server, but what would you prefer less security or more customizability". There are ways to protect against someone taking passwords, such as making the login and all of that unable to be "modified" by plugins or even associated with them. It wont load the plugins untill it connects to the server and passwords shouldnt really be cached in memory or anything.
either way I believe I gave a few other options on how it could work
