Earlier quoted context omitted.
The problem with this tactic is the need to go get the Yubikey every time you make a new account.
Actually, this is now a solved problem. Root-of-trust pattern. - Use Bitwarden or similar - Set BW to recognize the Yubikey as one (of several, incl. TOTP ('Authenticator') code) second factor. - On all other sites and services, generate passkeys (which are essentially virtual yubikeys) and save them in BW. - In BW, save the password and TOTP. BW itself, on another device (or in a separate incarnation - e.g. the desk…
"In BW, save the password and TOTP. BW itself, on another device (or in a separate incarnation - e.g. the desktop app when authenticating the browser extension) is now your everyday means of authenticating to BW."
Can you rephrase it and be specific which passwords and TOTP you mean?