If they forget their password, they can re-upload it from a validated device with a new master password.
If they forget their password, they can re-upload it from a validated device with a new master password.
Requiring existing devices to be actively involved in provisioning a new device prevents all of this.
So in Keybase, what does device to device provisioning look like? "Hey, you've just set up this device - a message has been sent to all your other devices, OK the message and come back here and you'll be good to go"
And if it's not a 2FA device, the victim can use 2FA to push a disavowal of the old keys and set up new keys. That's an ugly and server-centric solution, but "halp I got hacked" is going to be an ugly case no matter what.
All security is compromise though. And I think Apple has done something amazing with what is provided given their install base.