so you mentioned the security revolves around "trusted devices". what would the cotter login experience be like for someone who locks down their browser? i.e., blocks cookies, resists fingerprinting, etc.?
(Trusted device would work with browsers in the future when WebAuthn is more widely adopted. https://webauthn.io/)