The server does have to have access to the plain text password in memory, you know. I don't see why you think it's worth sacrificing guarantees of password strength to uphold some kind of taboo.
This should not harm security, but it can improve it if someone on the datapath is logging requests but does not alter them.
The only security benefit is that it offers a bit of support for those that are reusing passwords since it doesn't expose the plain text.
Not really. JavaScript crypto is fundamentally broken: an attacker, malicious server or disgruntled employee can replace server-side JavaScript and remove the client-side hashing at any time. This is, notably, why Firefox Accounts are completely and totally insecure (and hence why Sync is unsuitable for storing any private data at all).