If you don't do that and lose the certificate and private key, then you lose access to the account. You should not be able to log into the account without both the client certificate and the username/password.
The procedure I described earlier would be for accounts like HN or reddit. If this was an account with a government agency, bank, or credit card company, then the part where you generate a CSR and get a certificate would be done at an office where they verify your identity (drivers license, passport, etc). In the latter case, if you lose your certificate, then you need to go back and repeat the procedure to get a new one.
> Humans are fallible and will likely not maintain proper backups and such.
While that's true, we really ought to sacrifice some convenience for better security. If a user fails to maintain proper backups or register multiple devices for an account, then the inconvenience of losing their account and going to the arduous process of creating a new one is on them. They shouldn't put the lack of security burden on us by having companies engage in security theater like MFA (i.e., SMS or email based second factor) because they want convenience over actual security.
That said, those users could opt out of MFA and just rely on their username/password for authentication. Those of us who want MFA could use the client-side TLS certificate in combination with the username/password and keep our account secure.