The 'https://' disagrees with your 'sending clear text passwords' statement.
It’s clear text to the receiving server, which is what we’re talking about, not one way hashed.