- open up private browsing
- press F12 (or however you get the developer console on a mac) and go to the networking tab
- go to gmail.com say
- enter your gmail credentials
- look at the post request generated, and at the request tab, it will contain your password in plain text
So passwords don't get hashed on transit, this is why having HTTPS is so crucial, which is to prevent someone in the middle (say when you connect to an open Starbucks wifi) from sniffing out your unencrypted password. The password on the server side initially can be unencrypted before it gets hashed to be stored into the database. So in this instance, the password in the database is hashed, but there is a small period where the password is plain text in memory.
For a site called hacker news, it's really sad how little people here know about hacking.