I feel like the lack of an MFA alternative is what keeps me from dumping my smartphone entirely.
I haven't actually struggled much, here. I use hardware security (yubikeys) for everything that I can, and everything I can't generally uses TOTP, where I can use keepassxc. The one that has been annoying is a client who insists on using Duo, but even they support literally automatically calling me and having me press "1" to authorize myself.
- All 2FA I've needed so far works with any cell phone. They just text a random code to my flip phone.
- I'm far out of my depth here, but aren't there hardware tokens for this purpose?