It is true that passwords are not encrypted in the Users and Groups file on the
server. The theory is that the file is not accessible over the network and
that a server requiring security can be locked away from prying eyes and
software.
You are correct in stating that the Random Number Exchange method of user
authentication does not send a password over the network unencrypted. Be aware
that some third-party AFP servers may not support this method (although it
would be unusual), and the user has no control over what user authentication
method is used. The server being connected determines this. For a more
detailed description of user authentication methods available through the
AppleTalk Filing Protocol, read "Inside AppleTalk" pages 13-28 through 13-30.