Even the big guys have problems keeping passwords secure once they leave the browser. We really need to move to a scheme where something like SRP [1] is the norm, and is enforced/encouraged by the browser through special chrome on password fields.
[1] http://srp.stanford.edu/whatisit.html