So let me get this straight. We currently consider it poor practice if passwords are stored for authentication purposes in anything but heavily salted PBKDF2, bcrypt, or sometimes scrypt. Yet it's okay to just send SHA256 unsalted hashes to web services for the purposes of verifying that those same SHA256 hashes aren't already stored?
It's good that Google is encrypting these hashes, but come on, really? Surely there has to be a better way than just shipping off unsalted password hashes to a centralized location.
Edit: Okay, unsalted scrypt for the password. Thanks for the clarification :)