Step 3 is not possible without one of the following;
GitHub keeps a copy of the password in plain-text
GitHub keeps a copy of the SHA1 hash of the password
GitHub cracks the SHA1 hash and checks against their hash
GitHub calculates the SHA1 hash of the password after a valid login
The 4th option is the only sane approach, but it means you can't 'Check if passwords are the same' in bulk, only as users login.