The author is 100% not wrong, but the problem is that, unfortunately, it is entirely possible that Google cannot have an authentication system that is correct for use by the elderly in a shared-machine environment while being correct for everyone else at the same time. There are options to fix this, but they're social, not technical. To get there, let's start with the technical side of why the author's proposed fix w…
This. I wrote as much in an earlier comment. Why not allow the option to delegate a trusted third party to manage $ACCOUNT MFA flow? I'd use it (and kind of already do, via the recovery email addresses) for managing my aged parents accounts.
This seems like not that hard in terms of implementation and UX. What is the risk/expense from the libraries PoV you are alluding to?