Earlier quoted context omitted.
>> Basically, the ability for someone to log into my account by brute forcing or obtaining my credentials > you ensure that people cannot log in with credentials, even if they have them. Except that you left out the second part of that sentence: >> or being able to bypass the log on process by using the conventional second auth factor against me (by doing the same thing to my email account and/or my cell phone provid…
When technical security items have been pointed out repeatedly to you, you keep answering without addressing those security points. A valid security design should understand the threats that are being guarded against instead of simply throwing out a favored design.
But rather than addressing the issues where a 3rd party serving as a second factor/step can be compromised without the account holder realizing it in time or the fact that U2F doesn't support other protocols besides HTTPS, you keep going on and on about "security points" which appear to be nebulous in the context of this discussion and also cherry-pick my responses only to go off on a largly irrelevant tangent.
This discussion could have been useful, but, unfortunately, it didn't turn out that way.