New European regulations require that soon bank transactions over a certain amount must be secured not just with a code from a code card, but with a more reliable authentication method. In the comments on Delfi, where the abysses of hell always open up over any little thing, the howling and shitstorm immediately started, like, they're going to force everyone to buy code calculators, blah-blah-blah.
Carrying a code calculator (a little box with a screen) doesn't exactly appeal to me either. I think that in the age of smartphones and biometrics it's an anachronism, just like the code card, which I constantly spit at. Not only do you enter a code to log in, but be so kind as to do it for every single operation. I get that they're protecting my money, but somehow PayPal gets by with less bloodshed, doesn't it? PayPal itself is quite the turd, but that's a topic for another conversation.
Code calculator
In the end, the bigwigs at Swedbank decided that authentication there will be pseudo-two-factor, using SMS. Many people, I think, have encountered this in Gmail and other services. This would all be fine, but it's not a sufficiently secure method, see below.
https://www.wired.com/2016/06/hey-stop-using-texts-two-factor-authentication/
In short, a hijacker can intercept and redirect your SMS to another SIM card by convincing the operator that they are you, or with the help of complex technical means like fake cell towers. This has been done multiple times in Russia and other countries to civil activists, and simply for the dough.
So what's the solution? An app like Google Authenticator on your phone, which gives us real two-factor authentication. Unfortunately, there's little hope — even if Swedbank gets its act together, they'll release their own, less convenient, more janky, and most importantly — yet another app, even though Google Auth allows adding as many third-party services as you want. Ultimately, it's going to end up so that you'll need a separate app for every sneeze.
Especially since Google has a good track record from a security standpoint, and I don't think they will do any better at Swedbank.
They also bolted on authentication via the electronic signature from the e-ID card, which is like a passport here, but I haven't looked into it yet. The description looks like a bad joke — first you install the state certificates, and then you constantly have to enter a six-digit PIN. At least it's already better than random codes from a card.
e-ID card reader