My bank has a password - I never use that one anywhere else, but sometimes the bank calls me out of the blue to confirm some actions / bigger transactions and then I need it.
Turns out, when I can't remember it they tell me the first 2 letters!
They must have some advanced crypto where the customer support person can only see the first 2 letters but the rest of password remains securely hashed...
:) Even if it were securely hashed, giving out the first 2 letters reduces the range of guesswork substantially, especially when combined with wordlists. Also, the service-guys have to see my password, after all, they are immediately able to tell me whether I "guessed" the right password.
I don't believe there is any hashing going on, after all, the bank in question is ANZ, they don't even use TANs for online-banking.
Turns out, when I can't remember it they tell me the first 2 letters!