> User's authentication token was eaten by an alligator.
> User's phone, laptop, and hardware token were lost by an airline.
> User's phone and backup codes were simultaneously lost in a fire.
There should be a recovery process. However, the recovery process should be tedious and thorough enough to reliably authenticate the user and not be vulnerable to attacks. Charge a cost for the recovery process.
> because every time you have to fall back to human customer support it's $$$
Sometimes, "fuck off" can be the right answer, especially when the downside is a vulnerability that ends up costing more in fraud/reputation/legal liabilities.
House doors don't (yet?) come with a "forgot your key?" button, and the world hasn't ended, so it seems like most people are able to keep track of physical keys and have no problem paying a locksmith to break & replace the locks if needed. Safes don't come with those buttons either, and yet safe manufacturers haven't gone out of business because it takes significant cost, time & effort to open one if you lost the key (that's the whole point of it).