That's not stupid, that's just how folks who have other stuff to worry about in their lives, do with a technology they hardly understand. Security frameworks even for banking systems primarily depend on passwords and little else. It's similar to "getting past the gatekeeper to the fort, and then having access to the Armory, Queens Chamber and the Royal Safe". Access should not be granted because you could recite 10 characters in the right order. It should be granted after having fully understood the context of your attempt, the history of the account and the account holder, and doing KBA (knowledge based auth) commensurate with the damage that could happen if the wrong person accessed that account.
Passwords should die a horrible death. They are a mere fallacy. An illusion of security.