It's quite easy to come up with a scheme to manipulate the password client-side. I'd assume an organization with any technology credence whatsoever knows not to store unencrypted passwords by now.
McGill does some beautiful IT admin stuff. And then it does some scary-ass shit like this.