This is because the security of "2FA" isn't really from the fact that there are two factors, but that one of the factors is kinda just ok, and the other factor is ideal. A password on top of a proper 2FA method doesn't actually add any security to the typical login flow.
> So we’re back to one factor that’s ultimately secured by a device password/passcode anyway.
Unsure of exactly what you mean here - in what way is something like a yubikey secured via a password? Also, even if that were the case, changing the scope of passwords is important in and of itself.
> Plus if/when you’re not able to access the device, it’s much more painful to deal with.
Agreed, this is the big problem to solve - essentially this is just a subset of the "recovery" problem. It's one place where passwords may still fit in, though in a different role.
Ultimately, verifying identity at scale is just extremely difficult, and there will never be a perfect solution to recovery, but I think that we can mitigate that quite well with things like:
a) Phones as 2FA devices/ recovery devices
b) Multiple devices (ie: if we can reduce the cost of hardware tokens by an order of magnitude it becomes viable to buy 2+ for many more people)
c) Slower recovery methods that involve leveraging multiple identity methods - things like validating a government issued ID, mailing address, etc.