Instead of two-factor-only apps, we get "electronic ID" that are legally like a photo ID, and which are also used for making payments from the phone itself.
In fact, some of these rely on security of the OS it is running on, and not on the use of any trusted platform modules ("secure enclave", TrustZone, etc.) or on any mathematical proof. Therefore, un-rooted recent versions of Android and iOS is compulsory in practice, because those are the only environments that are secure enough.
And BTW, the electronic ID are very convenient for the banks. If they get social-engineered and the banks' API abused, the banks can conveniently blame the victims — because it's a legal ID and not merely a login helper or debit card, and you're not supposed to be "careless" with an ID.
The underlying protocol is a national standard (published by DK, the association of German banks) and meets all European requirements.
I don’t do business with banks that require iOS or Android apps for 2FA unless they support an alternative.
* Physical hardware (what?)
* SMS at 9 cent each
* An app
Why not? If you say "security reasons", then why is SMS allowed, since it's way less secure?
> SMS at 9 cent each
What places still charge for SMS?