Without proper encryption, an attacker can not only read requests and responses, but also modify them. This means that the attacker can modify the Login.html page to do no encryption at all.
The behaviour of the actual server is no longer relevant, as the client is talking to the attacker and not to the actual server.