And those same methods you mention are how people get "hacked". Everything that would make it easier for your parents to recover their account also make it easier for someone to social engineer.
The H word is such a lazy excuse. Techies overestimate how much the common folk give a shit about getting hacked. 99% of the population are not celebrities.
I know a bank that purposely reduce their Internet banking security. To cater for specific elderly customers who constantly forget their password. They are not going to force their customers to walk into the bank everytime.
These accounts are at a risk of getting hacked. It's called a tradeoff. As a bank, do you want customers or not? Do you like money or not?
As for the Yahoo situation. If they gave a shit about customer service: they can accept copies of drivers licence/passport signed off by a justice of peace.
Sounds like a bank that doesn't want my business. And that's fine if that's how they want to operate. But if a company wants my business, lightening security standards is not the way to get it.