Dennis Indeed. Thanks for the feedback.
That (#5) can iindeedbe done like you say. Hope bunq will pick up this sort of ideas.
Limiting the nr of popups for that purpose in a timeframe is however something to consider. Preventing a malicious actor in flooding the systen and you(r phone) with popus. Increasing the change you press agree ( by mistake/to get rid of it)
Once you have the mfa stuff developed and in a security token exchange under the hood (like iodc/jwt) the rest can be incrementally added quite easy as well.