Earlier quoted context omitted.
> Yeah, and it requires me to use a U2F token, which I can loose, etc. In which case there are much safer recovery mechanisms available. For example, a second U2F token, or handwritten backup codes. > and SMS as a second factor seems like a perfectly reasonable balance. My point is that it isn't. Unfortunately, today, identity is a true privilege - it pretty much requires purchasing multiple U2F tokens, and that's su…
> In which case there are much safer recovery mechanisms available. For example, a second U2F token, or handwritten backup codes. Which have either higher costs or "administrative burden" or both which will lead them to failure for a big chunk of non tech-savvy people. Educating a casual user that they need to print out recovery codes and store them in a safe place it's not exactly top notch usability.
So then have two U2F tokens. Or use your phone's TPM as a U2F token. The usability of phone-based U2F is quite good.