It would be great if online services showed a clear matrix of authentication methods so you can see which combinations are sufficient and necessary to access your account. Simply adding a 2nd factor is a bad idea because it means if you lose either one, you're locked out of your account, so you also need a 3rd factor to protect you from yourself. I personally have 4 factors for my gmail account - regular SMS 2FA, a friend's phone number for password recovery and paper backup codes. This way, I can lose almost any two factors and still have access. If I forget my password and also lose access to my friend's phone for password recovery, then perhaps I'll be in trouble but Google doesn't make it clear if they'll let you in using only your backup codes and 2nd factor phone number.