This is a really common technique in the UK, especially with online banking. “Enter the 1st, 4th, and 7th characters of your password.” Apparently the point is to prevent replay attacks.
The problem with telecom companies is they have customers from a wide spectrum of technical capabilities. Their systems need to be able to support the baby boomer who calls support because they can’t remember their password, pin, or something...
I’m not defending these practices by any means, but these society-spanning institutions are facing challenges of balancing usability and security that many companies do not need to worry about.
If a company wants to implement a system like this, fine. But please tell me before I enter my password so I know not to reuse another password of mine.