Correct. If having user service passwords stored in our database bothers you, log into a shell account and change the password with "passwd". We'll pick up the new password hash on our next user config and store the password internally as "changedbypasswd".
You can also view MySQL user passwords by clicking on the username in the panel (https://panel.dreamhost.com/index.cgi?tree=goodies.mysql). This shouldn't be a big deal, though, as you have to store the passwords in the clear in config files anyway.