I think your point is valid. Setting the flag is probably unecessarily cautious for the places you mentioned. I think for passwords and keys it should still be set.
If we assume that its rarely being set, I think there is a good reason for propagating it in string operations. Otherwise, it seems difficult to use it in practice, since its often impossible to make sure all intermediate values are being flagged.
On Wed, 14 Aug 2013, Martin Nilsson (Opera Mini - AFK!) @ Pike (-) developers forum wrote:
So, no one against reverting then.