> This pseudo-security measure actually only slows down humans, not bots, because you can still edit the value of the text field using Javascript I don't think this is a defense against bots. Virtual keyboards were created primarily as a defense against keyloggers, IMHO.
Are keyloggers that can’t capture screenshots still prevalent? I’d expect any software that can log keys to also be able to take screenshots, so the only thing this could potentially thwart is hardware keyloggers but they’d be a very small minority. TLDR: this is indeed BS security theatre along the same lines of blocking password managers.
Your browser will probably remember your password afterwards, so the usability decrease isn't even that bad. And that's not a security flaw either, because hardware keyloggers don't see the autofill values.