I honestly don't know what's going on behind the scenes to know if this is not as secure as it "should" be. But this was my reaction specifically to the non-SMS TOTP 2fa: Wait, if I lose my phone there's literally no way possible to get in? Oh there is, if I have the backup codes... yeah right, you think I can hold on to backup codes? Surely there's something I'm missing, what is everyone else doing here? Oh, everyone else is just hoping they never lose their phone? Really?