The only way WP can auto update is by the user giving away its credentials. The user should never store such credentials for others to read (in particular plugins).
Furthermore, FTP should never ever be used as it is a very insecure method of file transfering.
Of course you could always make your entire cataloge writable by the web server. You might as well email your password to the NSA right away.
So fracking stupid.