You can choose to not use the app.
The bank has a choice on how customers interact with it.
The government, regulating banks, and often acting as insurance for lost money, has a choice on setting required security standards.
Balancing all these is difficult.