They are encrypted so that only the server can read it.
yes, we need at some point client sided password protection,using the server domain/IP as part of the encrypted key.Means, a unique, crypted password for every single server,where the server owner can't decode the password.