04-06-2011, 02:12 AM
If this was a web game (and it might yet be), I would agree. This proposal specifically dealt with email, which is an unencrypted medium (well, no one has asked for my PGP public key yet...) , so any sort of encryption in the passwords would be vulnerable to a replay attack.