When a user changes their password using the web part, is it sent over the network using clear text or is it encrypted. If clear text, is there a way it can be encrypted without using SSL?