The only thing I ask these services is that they won't let anyone in who doesn't have the right password. I think it's not too much to ask.
It's silly to think Google doesn't already know everything about every device you log in from, so that horse is already out of the barn and running on the highway privacy-wise. They might as well use that information to actually protect their users since they're already using it for advertising.
You CAN add a phone number, then ask you use FreeOTP token, then delete the phone number. Great, right?
No. Because if you click that "I forgot my password / don't have access to my 2FA" button, they do let you use your phone number to identify yourself, even though you've deleted your number from your google account.
Fuck these people.