He mentioned login attempts in the article. Someone tries the wrong password more then a few times and the account gets locked. That should thwart any and all dictionary/brute force/you name it attacks. So which is more secure, an impossible to accomplish remote attack, or a password sitting on your desk?
Bank password polices are retarded. I currently have one that requires 6 characters. No more, no less. This may be the worst offense I've seen but it doesn't excuse the other bullshit that passes as secure or acceptable in the banking arena. These guys need help.