The logic is sound if you take the stance that phishing is the biggest threat to security. I don't know whether it is or not, but XSS and CSRF at least are under the website developer's control. Malware and phishing are the head-scratchers for people who know how to build secure websites, and the information card system does partially address the phishing problem. It prevents the attacker from being able to log into your accounts, but it doesn't prevent you from telling him lots of other things.