If a large percentage of computer users who use the library exclusively have ID, the library could purchase a MF device or cheap android phone running an MFA app and use the same device for every user or many users: show your ID, librarian verifies that you're registered, and then come over and log you in with key + username (user still enters password). Would it be possible for some nefarious person to grab these ke…
Forcing public libraries to use a workaround to fix a problem Google created isn't an ideal solution.
OTOH this library use case is a specific kind of outlier: I imagine this issue occurs in most/all libraries; it's a situation where changing the level of security is worth the tradeoff; it doesn't affect the security of anyone else; it's relatively inexpensive.
I don't consider this a "blame the victim" solution to the problem. I see it as an accommodation for people with specific but special needs.