But they could always do that with regular passwords.

Like, no company should be storing anything but a salted hash of their users' passwords.