> impossible to steal money from me without these things
First of all, "stripe" pushes information to the BankID app asking for confirmation, there's no code to input to the site, the verification happens on my phone where I'm asked if i wanna authenticate X or Y to happen (logging in, or transferring money)
But yes, they actually saw an attack vector where people could be fake challenged at the same time they're logging in themselves if someone knows they're about to log in.
This was solved by putting a QR code on the Bank website (and others that have implemented this so far) to be scanned by the BankID app. So now to steal money you would have to pwn the HTTPS between the bank and "me" or pwn my browser, or pwn my entire machine.
Also if you get 2 BankID challenges at the same time they cancel both of them.
Anyways, point is that without my phone and my own personal code being entered after a challenge where I see who's challenging me it's impossible to get money out of my account. It's designed to be REALLY hard to be tricked into authenticating someone else.
This system doesn't care about SIM swaps because it doesn't use the carrier network for anything other than encrypted communications with the BankID service.
I don't think there's a more secure system deployed on this wide of a scale anywhere and I'm quite happy with it. It's a PITA if you lose your phone though since there's no fallback method other than getting a new smartphone.
Nitpicking on words seems a bit below the standard of discussion I want to have though, and it seems like you thought it was just SMS verification. We're not cavemen across the pond, we're people just like you.
A nice benefit of this system is that when I call my bank I'll input my social security number in the system and it'll challenge me with a BankID challenge meaning the bank person knows they're talking to me. It's useful for a lot of things and at the same time VERY privacy invasive. Also doesn't work without a connection on your phone, but we're quite connected here so it's usually fine.
CC purchases in person are not authenticated with this system, we rely on the NFC thingy or chip. Magstrip isn't used anywhere here anymore. The bank covers all fradulent NFC charges without pin entry (which is why they're limited to 40$).
If you're curious for more information about BankID they have a site: https://www.bankid.com/en/ I think it's owned as a collab between "all" Swedish banks.
We also have electronic mail via a system called "Kivra" that the government will send mail through to me so that i don't have to rely on someone not dropping my mail. Also privacy invasive of course, but quite convenient.