Didn't NIST just say two factor via mobile is a "bad idea"? Have Norway or Estonia responded?
EDIT: Thank you whoever downvoted an honest question that added to the discussion
EDIT: Thank you whoever downvoted an honest question that added to the discussion
The Estonian method is described as using a private key present on the SIM card, just like a normal smart card used for authenticating/signing.
Besides, pretty much all banks simply use 2 or 3 factor authentication as an anticompetitive tactic (half the businesses in most countries pay the banks 2-300$ per month just for scheduled download of transactions)