

If you’re doing hashing and salting on the client then yep it’s useless, no difference to just using a hash output as a password.
If on the other hand you’re doing a zero-knowledge password proof method then it’s quite secure. As the password is never transmitted over the network, not even the server knows what it is, but can still verify the user has the correct one.
They are, that’s why the US has sanctioned them, hindering the investigations into what’s happening in Sudan, etc.