It's just infuriating, because credit card companies are the ones behind, for example, PCI. Which has guidance like:
"8.4 Render all passwords unreadable during transmission and storage on all system components using strong cryptography"
"8.4 Render all passwords unreadable during transmission and storage on all system components using strong cryptography"