If I'm building a service that needs an account system with 2FA, detection of automated attacks, and some decent amount of internal security, I am surely not going to build it myself. It is just like rolling my own crypto in all the wrong ways.
There are a couple of providers that will do this for me, for free: Google, Facebook, Twitter, Amazon, and GitHub come to mind. Each has some tradeoffs of public perception, losing audience members who refuse to have an X account, etc., but it's mostly a tossup. For a technical service like this I might have gone with GitHub, but if they're owned by Google, having only Google logins seems like the right choice. (Among other things, you already have a Google account in a sense when using Firebase, it's just run by a separate team at Google.)
Sandstorm, a project that encourages you to self-host all your web services, came to the same conclusion:
https://github.com/sandstorm-io/sandstorm/issues/150#issueco...
Is there a better third-party alternative here, or a way to do this securely and easily yourself that I'm missing?
Firebase apps can keep on logging users in via github, facebook, many others, and yes also google. It's up to the firebase dev to config that.
There are also numerous existing open source TOTP/HOTP 2FA systems.
Yes, you will likely need to do a little work to make things work together - but you are a software developer.
Using these existing systems is not like rolling your own crypto, it's like building your app on top of an open source crypto library.
I don't have an existing Google account and I don't want to sign up for Gmail, Google+, or any other Google services. What should I do?
It is easy to create a Google account for any existing email address without tying it to any Google services. It will only be used for identification and login. You can sign up for this "slimmed down" Google account here. You can also create this type of Google account via the existing migration flow on firebase.com.