> You could store [2fa backup codes] in your password manager Aaand we're down to single-factor authentication: your password from your password manager plus your backup codes from your password manager. I do recommend a password manager, but not to keep would-be-two factors in one vault. Also the very first item in the guide makes a blanket statement about dictionary words being really crackable. I forgave that one…
> Aaand we're down to single-factor authentication We're not, not really. The only single password that can unlock 2FA is that for the password manager, but most phishing attacks I'm aware of target the specific services, not password managers, since it's usually way easier to fake a banking login. Good password managers will have dedicated apps, so entering that password on some janky website is not something victim…
We are, by definition down to single factor if you store the codes in the password vault. The argument wasn't that therefore the system is weak, it is just that the point of having a second/third factor is to add something that isn't already present in an attack against a system.
One example would be that you leave your desk momentarily with your password vault unlocked and someone decides to quickly use your account to login to some system. Single point of failure. If you had the codes on a cellphone instead, firstly there is more of a chance that you would have taken your phone with you but even if you didn't, that "attack" now needs to access your phone as well.
Not all attacks are strangers and not all are malicious, just somebody elevating their privileges via your status is an attack in the broadest sense, even if they did it for respectable reasons.