2FA by SMS because of the deep invasion of the US telco sector. Possibly, more widespread but no five eyes warning to match yet, it's possible this is a US specific risk because of the telco sector specific issues.
2FA by totp is still my goto. I don't entirely like passkey but for no specific reason beyond finding its "janky"