LSASS.EXE is a valid process.
The card looks like a credit card with a numeric display. I press a button on the card and it generates a number that is unique to my account and I then enter that number to enable the online application. Even if the keystrokes are captured, the number is only good for a single use.
Someone who wanted to access my account would have to know my password AND possess the card.
Most banks and brokerages now offer some kind of security beyond simple passwords. Check with yours.

∆∆