As I see it from a glance over that bug report those passwords are used for authentication against other services and therefore must be present in cleartext form. Owncloud is supposed to run unattended, right? If there's no user to ask for some kind of password for the passwords with what key do you want to encrypt them? On machines without a TPM or similar there is no way to do that. Storing the passwords in the clear instead of obfuscating them is at least honest and doesn't provide a false sense of security.