Everything’s said already, e. g. @ Secrets.yaml security.
Having so critical information in plain text is a no-go from a security point of view. Once I have access to a HA instance the first thing I’d always look at is this secrets.yaml
file.
Why not hashing stuff after providing it in plaintext once - or finding other smart ways to in the end avoid storing secrets permanently in plain text.
To every potential new HA user reading this and potentially being scared of it cause we have 2022: overall security of HA is great! It’s only this little legacy piece. Start using HA