@BenAveling My original post was implicitly about phishing.
The banks claim the reason they only ask for two or three of the letters is to prevent replay attacks (capture via phishing or man-in-the-browser) from being used to login.
This feature is touted as a sort of one time password MFA, but it absolutely is not.