For practical purposes, that counts as "in the clear". Password should not be encrypted, they should be irreversibly hashed. (Preferably with bcrypt or scrypt or something meant for this use case; in this case I mean "hash" just in the technical sense of "irreversible", not that any ol' hash function is fine.)