I just wish they offered Two-Factor authentication for "360" accounts.
Relevant link: https://www.facebook.com/CapitalOne360/posts/101515573342295...
On an unregistered browser, someone has to guess the answer to two security questions and the PIN. Did it occur to you that maybe it's not a problem since it's been that way for at least 8 years now (I signed up in 06)?
It also allows you to only authorise specific actions e.g. transferring a specific amount to a specific payee, so protects against replay attacks.