Bugs can happen.
One of the first scenarios that comes to mind - some implementation queries API for every key press. Suddenly you are sending your password out.
I guess time will tell, but human-generated passwords have proven their ineffectiveness anyway.