Some banks do it properly. For example, my local credit union does Google Authenticator (actually TOTP, but they call it Google Authenticator). I use it with Authy on F-Droid.
Best thing that ever happened in this bleak security world is Google Authenticator. I haven’t used that app itself in years, preferring others, but the existence of it and it being non-proprietary, has done a lot to bring over the moderately-security-competent companies to thinking “hey, I guess we should support this.” Obviously that group excludes every American bank, every power utility, etc. They all want to email or text me a freaking code at each login for some reason.
Please do not use Authy, lacks essential features and it was bought by a bad actor.
Is there a way off Authy yet?
I recommend KeePassDX from F-Droid for TOTP.
Can you elaborate? Is twilio a bad actor?
wait, which bad actor? I use it for everything and hear about it first time
I switched from Lastpass Authenticator to Authy after the hack. The lack of the "upcoming key" feature has been a huge paint point.