I just trust the built-in encryption, which makes it easier to read via keepass2android (since I don't have to do an extra decryption step).
What kind of 2FA setup do you have?