What if there are no passwords to start with. If users do not enter a password and instead a hashed key is generated for the device used by the user which then encrypts everything before it is stored on the server.
This key could be generated in real time and would not be displayed anywhere on the form and will be transferred in stealth mode to the server.
With no passwords to enter or transmit, there will be nothing to hack.... If the key generated in origin is itself a strong key decrypting information stored on the server will require first hacking the key which if not stored on the server in the first place will make life hell for hackers as they will require access to the individual devices as well.
Cheers, gurudatt