Users should be able to choose the two-factor auth mechanism they prefer, when multiple ones are available.