It would be possible to insert a JavaScript hashing algorithm in these pages, so it would only send a series of numbers derived from the login credentials. And that way the actual bareword passwords would not be transmitted. So, it's not like it can't be done.