I would much prefer to see a second factor like TOTP, U2F, etc as the problems with SMS based second factor are well documented, but I'll take what I can get.
I would much prefer to see a second factor like TOTP, U2F, etc as the problems with SMS based second factor are well documented, but I'll take what I can get.
That’s why proper banks should use 2FA mechanisms that will ask the user to confirm the transaction on a second device (e.g. photoTAN or similar).
Of course, this won’t help against attacks if both devices are compromised or you are using the second factor device to access the system, but it’s still better than TOTP.
And, of course, TOTP is still way better than SMS 2FA or no 2FA.
Unless of course your bank does some proper, additional verification for large volume transfers.
For anyone who wants to set it up you can find it by...
1) Logging into Easy Web
2) Click your name in the top right
3) "Password and security"
I'm not sure I understand why you believe SMS codes as a second factor compromise the security of the password authentication.
Or, sometimes, you don't even need login access; one notable attack has been to the credit-reporting systems, where to unfreeze your credit report (and thereby apply for new credit lines) the reporting agencies require your name, birthdate, SSN, and SMS verification. But if the attacker already has name, birthdate, and SSN... well, that's all they need to get the cellular ISP to redirect the SMS verification, as well.
So I really don't see how this makes security worse.