my solution is a combination of all of these things:
- I have three yubikeys — one at home, one on keychain, and one backup
- I have three accounts that are secured by these yubikeys: my email, my password manager, and my Apple ID. these are the core accounts that are Game Over if access is compromised or removed to/from all three.
- for these three accounts I have recovery codes printed
- the recovery codes and the backup yubikey are stored in a safe deposit box at my bank
- for literally everything else I use my password manager (1Password) with its built in 2FA
the idea is, anything other than those three accounts getting compromised is not a risk since they all have unique email address (Fastmail masked emails) and passwords. software 2FA is Good Enough since it is backed by hardware 2FA for my password manager. and if I lose access to one of those three core accounts, I should be able to finagle my way back in.
since I'm not adding hardware 2FA to new accounts, I don't need readily available access to all yubikeys at once.
as soon as passkeys are pervasive I will generate and store them from 1Password.
this lets me have relative convenience in a majority of scenarios with focus on reducing risk of being totally fucked out of everything. it's obviously too much for a normal person, but for a professional in tech, I find it appropriate for my threat model/risk tolerance