I guess it could be used to guess a password and then probe other accounts to see if the user has the same password across other programs. Or if the person trying to ...
Here's the thing - in order for a "password hint" to be remotely problematic, a person would have to read it and then sit there and try to guess your password. They could do this in offline mode, but ...