Reminds me of the banks with their "enter the first and fourth characters of your password"-type enhanced login forms. How are they doing that without storing the plaintext, then?
However your bank will have so much information stored about you that if your bank gets owned you're basically fucked anyway even if they don't get your password.
I imagine the servers that actually store this data however are secure to a ridiculous degree.