> A second factor allows a site to better authenticate you. It does not help you identify the site. That's correct. On the first visit (or enrolment). All subsequent visits (many more!) do identify the site, or rather they tell you that you're logging in to the same site as all those times before.
> All subsequent visits (many more!) do identify the site, or rather they tell you that you're logging in to the same site as all those times before. I don't understand what you mean. Something about 2FA does this? How?
The details are complicated, but basically: If you register the key at github.com and later get phished to visit githubverification.com, then the authentication will fail no matter what the phisher does.