What's the alternative? Password resets are for when you've forgotten everything, so there's nothing that could be used to encrypt them. And email is the only contact mechanism that works on everyone.<p>(FWIW I avoid the risk by not giving HN an email address)