But you're tied to Bank-Id/Mobile-Id. If you lose your phone (or it's stolen) with all your certificates etc, will someone be able to do bad things with your account?
So the mobile bank-id is one way that you can use to identify yourself to various bank and government websites, most places still have multiple ways to sign on.
The mobile bank-id is still passcode-protected. The way it works is that whenever I want to sign on to one of these sites, I just enter my public personal id number. The app will then wake up, tell me that someone wants to identify as me on site X, and to enter my passcode if that's correct. If you steal my phone and don't have my passcodes, you can't do that. And I can revoke existing certificates if my phone gets stolen so they don't work even if you know my passcode.