I agree that banks and other high value targets still assume that attackers somehow "play by the rules". I got a call not too long (maybe a year ago) from someone claiming to be with my bank. Their first line was, "To verify your identity, what's the last 4 of your SSN?" My response, "You called me, how do I know you're actually with (bank)?" The rep was flabbergasted at the response and didn't know what to say.<p>Finally he gave me a number and suggested I call him back at it. Same problem. He gave me the number. It's a random phone number. I ended up looking up the number and confirming it was associated with the bank and then calling him back on it. Not ideal, but the whole security model is completely broken.