I've got an escape hatch for most of my auth. An encrypted file with my bitwarden backup and recovery codes exists in a public not listable s3 bucket under a random uuid file name. I've got its (partial) name stored with friends without any context. I hope I'll never have to use it...