Cookies pre-date SSL, so how were they securing that e-commerce that existed before cookies?
SSL is largely irrelevant to banking security anyway. Actual security is built upon charge-back system. The underlying security model was designed when everyone trusted written checks.