Short answer: - Yes.
Long answer: Authenticator-based second factor yields codes that expire quicker, but they're not specific to the actual transaction you're making. This is a decent tradeoff considering that Authenticator codes are independent of your email address, meaning that you'll be safe if your email is compromised.
Authenticator codes are also arguably easier and faster to use. However, email confirmation codes give us an opportunity to send you a transaction summary with each code.
The best solution from a security perspective would be requiring both codes, and we're working on making this available.