I'd still prefer the TOTP approach though because it doesn't require any connectivity on the phone.
You should be using two-factor authentication for all your AWS accounts, especially the 'root' account that's tied to your regular Amazon.com login (I've always though this is a bit odd).
You should also never use that root account and set up IAM accounts for yourself and any other user (which also use 2FA).
Pay-as-you-go phones are advisable to use for two factor verification, as they are affordable and could be used only for this purpose. Don't hand out the number and you've got a nice disposable tool for protecting your accounts.
If the service you're using doesn't support it, ask them to implement it. If enough people did it..