@inmysocks Well, in most cases the password is stored in the database, so it's almost like stored in a file.
The thing is if someone manages to breach into the server, accessing the filesystem is not enough, in the case of the db. OTOH, having it in the db allows the attacker to just try to pry the db open. So, it's a matter of who you trust: A single program (database) or a plethora of programs (all living in your server).