Earlier quoted context omitted.
Password is already compromised, so this is a worthless step. And only seeing part of the password may cause them to think it's largely still secure or something. (Some people don't understand wildcards.)
Good point
Nonono really bad idea, because of shoulder-surfing!