This is not something new. Many VPNs use the logic that this is okay because if someone already has access to your file system you're screwed anyway. I have always disagreed because certain malware may only have one function to steal passwords. Especially when used by script kiddies. This would protect against such attacks.