Hello,
I am running the android app v4.1 and I noticed that if you go into settings under the servers section and access the server you set up, the password is not visible. If you tap on password it will display it unencrypted.
I think this needs to be encrypted and you should only be allowed to change your current password.
Thanks,