And they used an actually secure OTP dongle, eventually ditched by most banks because, yeah SMS codes and apps are safer............
It's now that a lot of people can't use any remote banking, because their bank's app is huge or refuses to run on their phone.
The EU mandates the 2FA method shows information about the purchase you're authenticating (timestamp, amount and cc used in my case), making unconnected dongles impossible to use. This makes me sad, but it does have merit.
FWIW I still use the website to do all my payments. I find banking apps to be madness - you're entrusting all your money to what is essentially a toy.
There are unconnected photoTAN devices that support this. They have a camera that reads a QR code. Some European banks use this. E.g. Vasco digipass 770
If mobile banking really wanted to be secure, they would support something like a NFC yubikey for transaction verification. The fact they fully ignore separate secure HSMs tells you what you need to know about their security.