What's the difference between these three tiers of authentication, then? And what makes it different from SMS-OTP (leaving aside SS7 security concerns and focusing on SIM swapping, which I believe is responsible for the majority of successful attacks so far)?