That makes sense, but from what I can gather from the app as it's been laid out so far, the password is doing two things...answering "is it you", and confirming that the domain is the one you intended to log into.
As to the "is it you" (or "is it still you", because you could set your phone...