> Also not storing hashes of passwords, because then it wouldn't matter what the input is.
That only tells you they don't hash the passwords in the client. Likely the protection ("protection") is for the input validation layer, not the password backend itself.