Me too. 2-factor security: something you have *and* something you know. Also the UK legal situation: it's the credit card company's responsibility to prove that you owe them the money, in a court if necessary. It's far easier to be categorical if the hardware you used is provided to you by the card company, so if they so much as mention malware it is their problem by definition.

