Everyone has a 2nd email, personal + work or school.
You could argue that both emails are probably accessible from an email app on the phone, but if the phone is stolen, then that's no worse than SMS or ToTP apps also on the phone.
You could argue password reuse, but if the address used for 2FA is never exposed to the end user after being set+verified, then the attacker would have no way of knowing the victim's 2nd email address.
Unless the attack is targeted... But if the attack is targeted, then we're back to SMS being vulnerable.
So, what it comes down to is 2nd email as 2FA is more secure and more efficient than SMS out of the gate... (and much cheaper)...
And, if I use a very obscure and otherwise not used email (with its own security + strong password), even a targeted attack has no better chance than a ToTP app on an offline device, like an iPod touch.
So:
- 1st.) ToTP on offline device (most secure, most expensive, most difficult to learn, hard to use),
- 2nd.) 2nd email (can be most secure, cheapest, easiest to learn, easiest to use), and
- 3rd.) SMS (least secure, mid-expensive, mid-learnability, mid-usability).
Why didn't we all default to 2nd email then, instead of SMS as a paradigm? Actually, was used, and still used by Gmail from the beginning (even in conjunction with ToTP now)...