I would prefer any relaxation of the security on OTP to be limited to the same IP. This is risk-based security that is gradually being promoted in the business world as well. It's fine to relax a security measure if and only if the risks associated with the relaxation is insignificant.