So I'm talking to a colleague who specialises in security. And he asks me how many times I've ever divulged my banking password over the phone. Aha, trick question, I say, they never ask for your password and they promise not to, so you're covered.
OK, he says. How many letters are in your password? I tell him. OK, he says, so they ask for two letters from it, and they ask this whenever you call them or they call you. How long would it take a fraudster, using that information, to work out your password?
I reckon someone could do it in five calls, easily. It's not a nice thought...