There should be an option (and I'd even suggest it should be turned on by default) to never fill in <input type="password"> fields from the defaults dict, as that may lead to password exposure through the browser's View Source function.
See http://pylonshq.com/project/pylonshq/ticket/573 for more background.