I didn't even have to read the body of your text to give you this answer because this question pops up here and there.

Long story short; You should be using a security token anyways:

A physical security token came with 1.0 and ARR. I have been using my 1.0 one ever since, it sits just under my monitor, love it!
I distrust that I wont lose phone/it will die somehow so I wont use the phone app, but you use what is best for you.

^_^)v