Your two points are related: because the password is masked and you can't see what you're typing to spell-check, it's worth asking the user to type the password again to make sure they spelled it correctly the first time.
That being said, I completely agree with you – I don't think there's much validity in masking the password field except maybe when it's auto-filled by the browser.
We have tested turning off the masking on various sites we've developed and in general users tend to freak out and think the site is insecure as a result.