They are used for most pairing sequences, but we don't type them in anymore. They are used more to validate that it's you that are connecting two devices.
Maybe? There are a ton of shitty BT implementations in the wild that will never get patched. This does seem quirky at first glance, but could just as easily affect millions of vehicles, as an example.
If I was so inclined, I would camp out in a busy parking lot with an antenna just to see what I could find.