"Why does my bank use 3 different off-site script sources on their login page?"

Perhaps because noone's gone through the courts and tested vicarious liability theories yet.

IE: If it's served up from your page - you're liable

