I seem to remember SE having the stance of "Meh" if your account gets hacked without using a token. They back up their authenticator in the way that if your account does get hacked and you have an authenticator, they'll give you back everything you lose.