I'd rather have a store that's on another piece of hardware with logging and rate-limiting. Unlike TFA, I'd consider this a strength, not a weakness, but right now the convenience price is extreme.
U2F is good but it's still only a second factor right now and the migration story is abysmal. If they can extend it to serve as a first factor and add a migration story, it would be perfect.
I'm less concerned about attack surface and more concerned about just not having to deal with the logistics of safely storing and syncing something sensitive that I could also easily lose or not have with me on a mobile device or freshly formatted, self-owned device far away from home. I also don't want to have to trust someone else to store it in the cloud for me, especially if that someone else is handing me a closed-source app to do that.
I have a configuration file that defines the silly rules required by certain websites and also allows setting an "n" parameter that rotates the passwords.
https://github.com/dheera/scripts/blob/master/passgen-params...
The actual password generator: