True, well at least in part. The username would be transmitted as plain text, but the password is inside the MD5 hash returned by the browser - not sent as text. I am not sure of the exact name of this method, but using other data known at both ends we can validate the 'secret' without ever having transmitted it.