SauRoNZA
Honorary Master
I know where it's positioned. The point is that a password so complex that you don't even know it doesn't need 2FA that is less complex. If my password can be guessed then so can the 2FA. That is a site design issue so 2FA won't protect you there.
Most 2FA I had to enter is 6 numbers so if they can crack my password they'll crack the 2FA in no time.
And I'm not talking about temporary glitches but in cases like where you lose your device or it dies or something. If you use 2FA you have to compromise it in order to stay secure or you risk losing access. The track record for 2FA recovery is abysmal. If you have it on 20 sites and you lose it you have to accept that on a best case scenario you won't regain access to at least 6 of them.
You’ve got it all very very wrong.
You could make your password non-existent and replace it with 2FA instead and it would still be super secure.
Also I’ve never had these issues you have losing access to my accounts. And I have TOTP on 30 odd and a Yubikey for the rest.
