yeah, I am not saying a hash would be perfect, but at least it would have been a REASONABLE level of protection. ie to get round you would have had to go to that rather extreme level, and even with your idea, with a hash, it would have shown some suspicious behaviour (to grab password when the hash was saved, would have to clear the hash so they input password again). but just to encrypt the password is rediculous.