I'm speaking as a naive end user here. BankID in Sweden turns 20 this year. I've been using it for 15 years. Started out as an app on Mac, Windows, now it's on your cellphone. People have critizied it but in 15 years I have yet to hear about a security issue with the app or the protocol. I have yet to hear about a problem with it. All I see are advantages. And Sweden isn't alone in using some sort of eID. So how come…
It doesn't run on my phone because it's supposedly "rooted". I have a new Pixel phone with AOSP and the boot loader unlocked. The app behaves like malware or spyware because they make assumptions about end user devices.
Then they only support SMS based 2FA, none of the standards like TOTP or HOTP.
There is this weird sense of superiority or superior quality with the "Made in Switzerland" label. It may be true for a watch, but it's far from true when it comes to software and technology otherwise. Everything is mostly trash.