Proper two-factor authentication

I agree the SMS authentication is very annoying and needlessly time-consuming. But I think supporting Google Authenticator is not a great alternative since it’s not much of an improvement. The best would be to support U2F so that we can use our hardware tokens to log in, as supported by GitHub, Dropbox, Facebook, etc. (I use a TREZOR, which also supports U2F).