[1] http://i.imgur.com/QCGPDWz.png [2] http://i.imgur.com/VdtGC4T.png
[1] http://i.imgur.com/QCGPDWz.png [2] http://i.imgur.com/VdtGC4T.png
Still a lot easier to guess a portion of a password than a password, but it doesnt follow in my mind that it is definitely in plaintext.
However this is a memorable phrase (not password), similar to a security question. These are not generally hashed because customer service uses them to confirm authorization to reset a password.
The "password/memorable phrase" is only used as a secondary authentication measure and in order to initiate a token recovery procedure on the site.
P.S. I still use the physical OTP token, just got a new one last month it's a Vasco Digitpass 270 supports upto 8 digit pins and it locks out automatically after IIRC 5 attempts.
I don't recommend using a phone authenticator for the sole reason that losing a phone is annoying enough on it's own you don't want to lose your bank account access too :)
Edit: I realise you're probably referring to proprietary bank authenticator apps
I really really dislike HSBCs online banking as a whole, the password system plus the constant “We encountered an error, please try again later” messages.