One thing I fail to understand is the experience of the author in making such a statement. As per his profile, he is an undergraduate student at NUS. I did check NUS's courses offered and there is hardly any course in hacking or teaching much about security. They just have a basic module on security which is not even mandatory. ANd the author is questioning the security practises of a company whose CTO has a 25+ years of work experience (Team page). He fails to understand the fact that it is not possible to do regular backups without the password. Something the user totally skippd in his article.