This is claimed in the linked Wikipedia article to prevent phishing but how could it?
If the phishing site presents a ui that looks like the real site, the user could be tricked into entering his real username/password which the attacker could then use to log into the real site.
Or am I missing something?