Quote from jimrockford:
No, it is not a stupid policy. Yes, others have access to your dob and mother's maiden name, but adding that extra layer of security of requiring that information does greatly reduce your security risks. Try thinking about it a little.
When customer has secure device challenge-response authentication in addition with email notification is enough.
Mother's maiden name or equivalent does not give any additional security.
With bare userid/passwd authentication situation is different.