My bank uses phone SMS as its standard "2-factor authentication" -- better than nothing at all but GROSSLY insecure compared to encrypted messaging that it refuses to supply.
I paid extra for an RSA dongle, but when I log in there's an option to use SMS, which makes the dongle completely pointless.
Crap security is standard in the banking industry -- because contrary to pious words, it doesn't give a damn about your financial privacy.