In the Netherlands the ING bank was testing the waters this year by holding back on announcing a non-smartphone alternative to their ageing authentication methods (either SMS or a list of pre-generated codes received by mail). All of their communication was bent on nudging customers to use their banking smartphone app, and only at the end of this year did they announce a separate hardware solution for customers who don't want to, or cannot, use a smartphone for their banking.
Every other bank in the Netherlands already had such hardware devices (TOTP usually, although newer generations use more complex methods) for a decade.
U2F and its successors are the way forward if we want to maintain some semblance of digital freedom, not tying your whole identity to a smartphone.
while i agree with you, i seem to lack the imagination to come up with realistic examples that i can present as arguments.
i am afraid anything i think of would get a response like "yeah, sure, but noone uses their phone like that" or they'll simply accuse me of being paranoid.
For instance I hate in the same way countries that ask users to install proprietary crappy software's to pay taxes instead simple pdfs/standard WebUI.
Forcing me to use a smartphone app means I can't use a normal desktop or laptop computer, or even a non-Android, non-IOS smartphone. It means that institutions that provide a semi-public utility (e.g., banks) force people to support and agree with the terms of use supplied by a (foreign) megacorporation to function as a citizen in the digital realm. That is inherently undemocratic and a threat to our freedoms.
Expecting the vast majority of citizens to have access to a computing device with a modern web browser is somewhat reasonable (as long as those who can't are supported by other means). You can at least choose what software you run, and there are free software options available. With smartphone apps (well-built web applications excluded) that freedom does not exist.
We can't trust smartphones/connected devices in general, that's why IMO is better, for safe auth only, use offline stuff.
Can you point to any instances where that's actually happened? Yes, sure, it's theoretically possible for someone to break into my fully patched phone and steal my 2FA secrets. But it's also theoretically possible for a mobster to break into my house, hold a gun to my head, and force me to log in to all of my banks accounts so that he or she can drain the money from them.
There is no such thing as perfect security, and I would much rather have people using a 2FA app on their phone than just username/password. Is it perfect? No, of course not. But insisting that the existence of phone vulnerabilities makes 2FA apps on phone unacceptable, and that the only form of acceptable security is for people to juggle dozens of authenticator tokens is making the perfect the enemy of the good. It's because of "advice" like this that people ignore armchair security experts.
A dangerous thing remain dangerous even before accidents happen.
that may be fine for some things, but surely not my bank account
I use NixOS so my OS will replicate autonomously, I have dotfiles managed via org-mode+stow (and trying homeManager), rsync and unison at hand. I'm pretty confident that I can survive many kind of crush quickly with enough safety.
My phone however is an entirely different story: I can't backup it properly, I have to relay to obscure, proprietary and totally unreliable mechanism that prove to being able to restore only parts of my phone "operating environment" and in an unpredictable manner.
What you can do with all your soft-token if your phone suddenly die?
Another example in the past banks have had bankbook on paper, essentially ledgers that banks and their consumers have in hand, so both parties can prove a transaction. Now it's all on bank's servers, I can prove nothing as a consumers, I can only hope my bank do it's job well. Same if you buy shares, in the past you obtain a paper document that prove the transaction, now it's all on someone else server. You can take screenshots, perhaps have some sort of pdf receipts but they have essentially no legal value, anyone can forge them. Credit card are the same, internally they operate like paper bankbook, recording a certain number of transactions, however you have no control on that.
That's the BIG point: it doesn't matter how skilled and provident you are, the systems it more and more designed in a way that you are TOTALLY powerless, no matter how many things you know and how attentive you are.
the phone i carry always around. the risk if loss or theft is always lingering.
my wife just dropped her phone. it crashed. took 5 minutes to boot, i guess a filesystem check after the crash. it could have died completely too. my previous phone stopped working because of a botched update. we had a phone stolen...
there are just to many uncertainties to trust a single portable device.