SMS is not secure. It can be faked. It goes through multiple networks. It's not encrypted. And if you use a GSM phone, this could be owned two years ago at DEF CON: http://www.pcmag.com/article2/0,2817,2367247,00.asp Not to mention the provider-specific attacks, cloning, etc. If you start pushing insecure technologies like this, people will just get really comfortable with them and eventually get taken advantage of.
Don't let the perfect be the enemy of the good.
A secured data connection is much better than SMS and easy to implement. But this is still a 'something you send' factor, which can be intercepted. A physical token or 'something you have' is more secure, and can also be easily implemented with a YubiKey, a paypal/ebay authentication card, etc.
If you think your data is so valuable someone might install a keylogger to get it, you might as well secure it as well as you reasonably can.