Suppose you lose all your physical keys: I don't think you can social engineer hack Coinbase (pretty sure most companies won't allow people to just give away your password/send a reset email to some other email).
Or suppose you get them to send me an email to reset my password. But my email also has FIDO u2f! And I know as a fact you can't social hack my email provider.
The Google Authenticator app on iOS doesn’t backup its keys so it’s pretty common for people to lose access to that kind of keys.
Which keys is it supposed to backup?
Everything else you said is sadly true.
Under the hood Google Authenticator uses keys to generate the codes you see on screen and these keys are not backed up.
It’s a difficult decision of course. If you back them up in iCloud Apple and people who hack your Apple account have access. If you don’t the keys are lost if the device breaks or is lost and you need a workaround.
Edit: oh you wanted to restore on the same device. Well that might work but it doesn’t help when migrating or if your phone is not available.
Then also setup TOTP, so if you lose both keys and have a working cell phone with the app installed you can still login.
Some websites allow TOTP which is still safer than SMS, but if I lose one, I'll get another one while I use the 2nd.
This seems really easy to steal.
> one at home
Most people I know have been burgled too.
It’s not so much a problem as it is a balance of security, redundancy, and effort. You decide where you want to be on that balance of considerations.
Yeah, good luck.
I don't know of any system that lets me enroll 3 security keys for an account.