If you're ever prompted to add a phone number to your account on some web service for "extra security", just click "remind me later" or "skip" as many times as possible.
They just won't listen. So give them a fine instead, that will make them listen.
The second 'wake up call' after the last one I've seen today: [2]
[0] https://news.ycombinator.com/item?id=29264937
To me, I'm too forgetful and dumb to not lose a yubikey, but I manage to not lose my phone.
What I ia m in a different country, visiting damily, and the ubikey is lost - am i locked out of everything?
For iOS users, I cannot say enough good things about https://apps.apple.com/us/app/otp-auth/id659877384. Author is responsive, encrypted backups, portable data format.
They don't offer any backups (at least on iOS) and as a result, if you lose your phone, you are hosed. Google Authenticator also doesn't use iCloud for backup for files like other apps. I also just assume at this point no one owns that app and that it'll never get backups because that's how Google operates.
I've seen multiple people lose their TOTP codes this way and have been locked out of their accounts. Or even the more simple case, they buy a new phone, restore from backup and just assume everything is peachy then send their old phone back and then don't realize it until they open the app for the first time.
Use something with cloud backups for your safety.
But since then I started actually backing up my recovery codes, and whenever I create a new account somewhere, I set up 2FA on three separate apps on my phone just in case.
Google Authenticator used to have no way to get the data out, but does now have an export. It still has no normal backups.
As for Android Google authenticator - there is export function, that generates QR code for all tokens. You can't screenshot it, but can take a photo with different device and print.