The only sane recommendation is to secure a SEPARATE device that is never connected to the internet and never auto-installs updates except maybe to sync time only if/when 2FA code fails. Otherwise you’re just 1 bad app update away from being hacked. It doesn’t matter which 2FA app you switch to.