yooooooo shhhhhh
Don't give them any ideas :(
Also it's not like insane security ideas around banking access compliance are unprecedented, see e.g. South Korea's insane Internet Explorer deal (transitively caused by US's ITAR on encryption)
https://en.m.wikipedia.org/wiki/Web_compatibility_issues_in_...
There is no limit whatsoever to what a bank feels is justified in doing when it comes to preventing fraud, money laundering or whatever else that impacts their bottom line. They literally believe they are entitled to any and all access.
Many banks in the EU require a smartphone for that at this point (or a dedicated authentication device).
But instead of using actually secure technologies like Android’s protected confirmation (which couldn’t care less about running on a rooted phone, as it runs in a trusted HW enclave), they usually just settle for (often very spoofable) “root detection”. It’s quite sad.
Needless to say, I am happy I have a second work phone I keep disconnected from WiFi while not working.