Same as you in that I resisted the need to move to a "phone for everything" as opposed to using a PC where I could control the environment the software ran in. But after Krung Thai removed their web front-end to online banking and went app only, I've installed and activated the app. And notwithstanding any insecurities which are not immediately obvious from casual use, it is useful. Booked some plane tickets in person on Sunday and scanning a QR code on the counter-top device and checking the transaction was right before hitting "Confirm" was a lot easier than making 4 withdrawals from the ATM and giving them cash. Same with household bills. I'm reluctantly seeing the benefits...
Anyway (for Krung Thai app)
1) It'll work over wifi or mobile data, so if you're only using wifi you should be fine (don't remember if it was mobile data only for install as suggested by OneMoreFarang)
2) Wifi only is fine.
There is no OTP. On install it requires a Thai ID card number, and should accept the NDID thing that farang can't get, so I did have to visit the bank branch to get it activated. The cashier knew what she was doing and it was painless. By default she set it to a fingerprint check for each transaction, though I changed that to use a PIN instead. So no OTP, but other secondary permissions are needed (though possibly could be disabled completely).