Earlier quoted context omitted.
(1) Users should not receive passwords via e-mail. (2) How very enterprisey of you to even be able to send passwords, which one also should not be able to do. (3) Users can change or modify their browser, either to another browser entirely or through installation of addons. The fingerprint is not guaranteed at all to stay the same or similar.
(1) There is nothing wrong with sending a password via email. Even if you send a reset link instead an email provider could steal that too. (2) The server gets sent your password every time you log in. You shouldn't rely on a server operator not knowing your password. (3) You can tune how sensative the system is in response to changes in the fingerprint. Even if their in a failure to match that just means authenticat…
(2) The server gets send the password via the default communication channel, the browser, TLS hopefully, not via e-mail, possibly into an inbox, that is third-party controlled (say some google mail inbox for example).
(3) That does not make it right. Did they even ask the users for their consent? Did they learn anything from GDPR or in general discussions about consent? Or are they just a higher being, allowed to decide for their users, what data about them they track?
Many things can be done using technology. The question is always: Should we do them? That is a question about ethics, not technological possibility. We already have far too many businesses not caring about ethics at all, we do not need any additional ones.