People are missing the point. The main reason for this is not to defend against "hackers" so much as malicious employees within the company. If you hash and salt the passwords, it's simply not possible for anyone within the organization to access them. Even if you trust all your employees, it can help in avoiding liability.