They exist for sole purpose companies can just shoot the "we have been hacked, but worry not your 'passwords' have not been leaked" email.
It's entirely one sided solution.
But they could always do that with regular passwords.
Like, no company should be storing anything but a salted hash of their users' passwords.
But they could always do that with regular passwords.
Like, no company should be storing anything but a salted hash of their users' passwords.