It's worth pointing out that AWS does now support U2F, which isn't reflected in the posts.
I tolerated that because a work account administrator can let me back in if I lose the key, but this is very much a second class implementation and I think AWS ought to do better.