Banks have your password, but when they verify you online or over the phone they ask for, say, characters 2 and 5. If the password is one-way hashed, how can they do that? If the hash is reversible, isn't that dangerous? And if it's not hashed, move banks.
So assuming they use a one-way hash, how do they do that?
Thanks.