As Sara indicated, they are encrypted. They can be cracked, but usually there's not a need to see the passwords. If you want to transfer logins to another SQL Server, there is a way to do so without losing the password, such that the DBA doesn't ever have to know what the user's password was.
K. Brian Kelley
@kbriankelley