Earlier quoted context omitted.
Yubico Authenticator is a fork of Google Authenticator and is a drop-in replacement. I have never had any problem helping someone that has used google authenticator set this up. Scan barcode and tap. Also users have a much easier time when they get a new phone. Just tap to new phone and get codes. There is no data to transfer. As for people getting locked out, that is what the printable backup codes are for, or a sec…
That's a desktop TOTP application. Now not only do they have to have their computer with them to log into their Google account from their phone, but they have to have 2 security keys on the account to remove their phone number from it, and all their backups are physically separated from them, so unless they bring their backup codes with them when they travel, if they lose their key, they're boned. And all this for wh…
The android app is a direct fork of google authenticator and has nearly identical UX.
I tap/plug my key to either of them to get a token.
If you want to make the argument TOTP via hardware token is overkill for most users, that is totally fair. On that note though, there is no point in having hardware token via U2F.
Security is ahout the weakest links. All I am saying is anyone going through the trouble to set up U2F as this guide suggests, might as well spend the extra 10 seconds to store their TOTP secret on the key as well, vs exposing it on the phone.
I assume someone that has a hardware token is getting it for a reason: To have assurances an attacker can't log in as them without that token.