I have USAA and they are pretty bad as well. Max password length is 20 characters. They only do MFA through cell phone numbers and email which allows someone to Sim-Swap if they are able to get your username and password. To top it off, they have a mobile app knock-off 2FA screen, but you _can not_ see it when you're trying to log in to your account via the mobile app because the modal doesn't let you leave the input screen.
I was going to write them an email, but they have no clear email to report security concerns so I figured they don't care.