Earlier quoted context omitted.
If you do 2FA without recovery keys or a recovery eMail, you’re doing it wrong. Everything I have heard from you so far is draped with ignorance and misinformation.
recovery keys = "write down your password" which they've been telling us to not do for years recovery email/phone = same threat model as regular passwords, and it's a big crack, all the time somebody bribes somebody at a phone carrier to take over the phone number of a crypto whale Practically low-touch services are going to have to resort to these things, but they render 2FA performative. Now at work 2FA is OK becau…
Like, this isn’t the 1980s anymore, password managers exist - even local-only ones - that can keep both strong passwords and recovery keys totally safe. KeePass in particular can be synced using server-free methods, keeping everything on-device, strongly encrypted, and essentially offline.
I suggest you touch some grass and actually educate yourself. TOTP 2FA is a massive leap in security that brings the traditional username+password safely into the modern threat era. Provided that the password is long+strong and the username leverages dot extensions in the eMail (if an eMail) or is a totally unique username (if only a text string), said three-point security can reliably exceed that of passkeys.