They aren’t forced to lock them down, or prescribe any app store afaik. That’s the banks that do. Some lock it down, some not at all. But you’ll need some form of 2 factor “photoTAN” app. Unfortunately, common 2fa codes aren’t used (or allowed), I think this legislation is actually older than them becoming common.
And that’s quite all, they also offer hardware token generators. Not sure if they are required to, but i think so. You do have to pay for them once (20 or 30 bucks maybe?). In reality, this is somewhat impractical for a variety of reasons…











I’m aware, but you’re not getting the secret token that you’d need to put into your TOTP app. At least not that I know of. I also haven’t checked in a very long time if there are open source reimplementations of the photoTAN apps. They all got their own flavors, but it’s also just a slight variation on a theme (initialize app with qr-like secret, then scan a similar code as a challenge/response using that secret to generate token). Probably should check that at some point.