However, if you can sniff the connection you can probably alter it and inject javascript that submits the clear-text password to the attacker.
The main reason we encourage people to use key stretching algorithms on the server is that, if an attacker gets access to a database of password digests that aren't very strong, they can trivially be reversed.
Doing this key stretching or "password scrambling" on the client side simply moves the processing burden from the server to the client. There is nothing less secure or less useful about it.
Until such time as these things are readily available, recommending that people do client-side hashing is absolutely going to result in trivially poor implementations.
You might want to consider that if these problems were as trivial as you seem to believe, there would already exist a library vetted by cryptographers to do exactly that.