That said, I absolutely also hate having only a choice of a 6 digit pin on a UI that's intentionally designed to disallow any password manager usage. Plus they shuffle the inputs, make you change pin every n-usage/n-days. I really don't get the rationale other than it maybe avoids screen scraping, or keylogging?
Apparently just SMS is not deemed secure enough by law, so they have to have another authentication factor, and the only other factor they have if you haven't activated certicode is the regular account password.
You usually only get the 2nd factor notification / approval on your mobile phone so you only enter it on the bank's app.
Banque Populaire. But others are no better. Société Générale is abysmal for example.