Why should I password protect WP-Admin?

The protection from .htaccess is for the folder /wp-admin it’s not for the URL

Open up your ftp programme (or download WordPress) and look inside /wp-admin

By only allowing your IP access this folder you’re blocking a lot of possible exploit issues (as mentioned in comments below).

I always prefer to login at mysite.com/wp-admin and not login.php this way, if you’re still logged in to your site, you go straight to the Admin section.