Remember, 2fa is your second factor. It’s right there in the acronym. It is there to protect against a bad actor stealing your password.
By definition, a second factor won’t improve the ergonomics of logging in.
Remember, 2fa is your second factor. It’s right there in the acronym. It is there to protect against a bad actor stealing your password.
By definition, a second factor won’t improve the ergonomics of logging in.
Many messenger apps already do something like this (using your phone numbers as a first factor and using an optional password for account protection) and IMO the login flow is much easier for services that I don't care about.
Let me register and login with WebAuthn alone and I'll be very happy. You can even use the same logic you're already using for password resets, just re-enroll the FIDO key when someone clicks "I can't log in" and proces access to their email account. Immune to credential stuffing and many other digital attacks that can happen from the other side of the world while you're asleep!
Without that the only benefit of a Yubikey over a strong password saved in a password manager is phishing protection, which I'm not willing to pay that amount of money for.
Malware on a device where I'm logged into the service can use that authenticated session to access all the things I want protected.
If the service is hacked, the hacker probably has direct access to everything the password was protecting.
Any well-secured service should protect critical actions with 2fa. “oh, are you sure you want to transfer all your funds? Please re-authenticate first”
If your PC or smartphone is compromised nothing will prevent you from losing control of your accounts.
The place where they shine is when you have already acknowledged that you want (or have been forced by your employer to use) 2FA.