Earlier quoted context omitted.
> Using smart phones as authentication devices suffers from this exact same problem. This. 2FA or "tap to login" is all nice until the phone melts down and - by design - you (normally) don't even have backups, so have to use recovery codes. Which aren't always available. > I have concluded the password is king. What about the keypairs? They are the same as passwords (when done right) - just long "random" strings of d…
> until the phone melts down Under what circumstance would that be considered normal, expected, or acceptable? My phone just doesn't do that, and never has. Sure it crashes maybe once a month or so, but then I'm able to use it again within ~15 seconds. I think that experience is mirrored by most people.
Using strong passwords and an auto-completing app like keepass, this is simply not an issue. I can log in from another device.
Also, reliance on mobile devices means reliance on some corporation's cellular network. Putting the control of your vital access into the hands of people who you know are not your friends and who would love to take more than just your money is never a good idea, in my opinion. When their system crashes you can't just reboot your phone to fix the problem, you can't do anything.. in fact. You have to sit and stew in the hell of your creation until their system magically comes back online. Not worth it.