Both of these reflect a security approach from early 2010s when keyboard sniffing was the worry-of-the-week. The idea was that even with all keystrokes intercepted, the full pw was never sent via keypresses.
One of my pals around that time turned on accessibility features like onscreen keyboards and diligently never typed a password. In a shell, a site, whatever.
It's unfortunate that these sites (Treasury and UK mortgage) were built around this time, but also shows that with all the progress with tech, security is still glacial in places. And like all tech, we get stuck with trends for a while (like skeumorphism in ux design).