This is a bit unrelated to the harder crypto stuff but my mom called me freaking out she couldn’t get into her gmail. It turns out Google auto registered her new android phone with a passkey and made that the default Google login with a confusing passkey based interface (expecting her to know to click the second option to login via password or understand wtf a passkey is was too much IMO). It turns out when it said “…
Honestly, I think if you’re using 2FA, you should also have 2 different ways to provide a 2nd factor (like TOTP or notification to your phone).
Losing access to my second factor has always been my biggest concern with 2FA.