There's an obvious tradeoff having an authenticator (2FA/OTP) separate from your secure password manager. If you lose the device with credentials, you're screwed. It's really easy to lose access to a device (and usually without advance notice). Or you can override the 2FA, and then you're back to hoping the verification procedure of overriding 2FA is stronger than a dedicated attacker. A password manager managing 10…
> Maybe the best strategy is a hardware key with printed backup code? Or register more than one (preferably three) hardware key. It sidesteps all of these issues. They are very resilient and act as backups.
Presumably you would need to obtain all three keys every time you register a new user account on a website.