> You can put an auth cookie in a browser and achieve 2FA for 99% of use cases without bothering anyone.
Confusing, obviously incorrect.
> No reason 2FA can't be just two passwords.
Maybe somewhat less obviously incorrect, but still incorrect. Passwords can be phished easily, are managed by users, etc.