If the host PC is compromised, does a cheap smartcard help? Just capture the PIN (like you would a password when they logon to their bank) and replay at will? Maybe if the user is very careful to only keep their smartcard in for the minimum time required it helps.
So long as other bank protections are in place, it shouldn't be a step backwards. If it's used to move all liability to the consumer though, then it's a problem.