Both my Swedish banks require two-factor authentication - you get a physical PIN pad when you sign up, and you can also set up a 2-factor app on your phone. All transfer amounts and account numbers have to be signed on the PIN-pad, securing you from man in the middle attacks that are possible with one-time-codes. They both also have password-only login, but it's read-only, you can't do transfers.
I wonder what makes the banks in the two countries have such different views on security?