if stored clear in the database and transmitted in clear between the pc and the server its not a password its an invitaion to packet sniffers
hash: Md5 sha or otherwise (md5 serverside | md5 clientside) the password and verification of the password on the pc at account setup, and transmit & store the hash in the password column
hash the entry password on the pc and send the hash for verification
nobody knows what the password is, sniffers can't read the password
Users will continually make errors in this 4th char 3rd char crap
even if you ask for their name as a password people will count characters wrong