I'm not sure that this is strictly necessary, since we're encrypting / storing with SHA & salt on server - and protecting clear text sends with SSL. Opening topic here in case people have something to say.
See conversation here, and crypto-browserify