In other words, you do have an in-use apple id at (pretty much) all times.
In other words, you do have an in-use apple id at (pretty much) all times.
Further: the three apps I install are not crucial - I could live just fine without them. All I really need is Safari and a working POTS endpoint for my cloud-hosted phone number ...
Not every service provider offers a web app anymore, and if they do, it's often penalized in terms of functionality or fraud screening hoops one has to jump through (since mobile apps offer device attestation and generally have a higher cost per bot action than browsers). Some even outright demand device attestation, which not only excludes non-iOS/Android devices, but even custom ROMs or non-Google-blessed phones, since they lack the necessary keys.
And yes, people could protest that by just not using these services if they're not strictly necessary to survive, but the dynamics here (tragedy of the commons etc.) just don't work in favor of individual people.
Web based online banking (since nothing related to banking requires 3D or VR/AR or camera/mic access or other fancy things that apps do) and 2FA auth. That is all I have ever seen or used.
By contrast, all European bank accounts offer outbound payments, which nowadays clear and settle instantaneously. The fraud risk is just orders of magnitude higher.
The US now has Zelle, which is actually showing just that friction and not going especially well for banks that were kind of blindsided by the sudden requirement to actually authenticate their customer, which is why you see all kinds of strange stopgap solutions mixed with proper security.
That's not the case, but SMS-OTP only counts as one "possession" factor, leaving only "knowledge" or "inherence" for the second one, and both are awkward to ask for in a payments flow. (You don't want to train users to enter their bank's password at a merchant site, and biometry/inherence isn't easily possible from an untrusted device.)
By contrast, doing biometry on a linked device provides two factors (possession of the device and inherence), and is significantly cheaper than SMS too. SMS in Europe can be pricey!
As a tangent, they are in fact banned from using email as a factor, which I find infuriating – my mailbox seems much better protected than my SIM card or phone number, which is one successful attempt at social engineering away from being swapped out or ported away. The SMS industry must be pretty good at lobbying.
https://www.wellsfargo.com/biz/online-banking/securid/
... which is quite simple and cheap ... and can be used in place of SMS 2FA.
The fact that these tokens exist and are so simple to deploy and use really deflates any claim (by banks) that banking and/or auth apps are required. It causes one to consider what the real motivation is behind the bank desperately pushing customers away from the simple and adequate web service towards the apps.