Can it be copied from your phone? (e.g. by migrating your phone via a backup) Then it can be compromitted and is essentially a single factor (because some website permit you to login via the key only). Only if you'd need to completetly renew the key, then it's truly secure.