I'd be perfectly fine with non-SMS 2FA, especially if it would reduce cost.

//