Basically (if I've understood it correctly), You get an random seed that you initiate the authenticator with, then for (each minute?) it combines the unix timestamp, the seed and calculate the time-based-one-time-password.
So combining a user-specific password, the TOTP (whose seed is on an initiated device for the user) you have 2 factors that can be hard for an attacker to retrieve both of.
https://datatracker.ietf.org/doc/html/rfc6238
(Kludgy? Maybe a bit but feels fairly secure in practice)
https://www.rfc-editor.org/rfc/rfc4226
FIDO2 with a hardware key source provides a much stronger and more secure guarantee than a 6 digit hash and an unencrypted symmetric secret stored in an app.
https://fidoalliance.org/fido2/
Any and all 2FA approaches demand backup codes (and backup code management with confidentiality and durability) to protect against 2FA loss or inability of the 2FA to function. For example, there are some apps that insist on performing FIDO2 on a non-NFC platform. While I can use a Lightning to USB-C adapter to workaround this limitation, it's possible that I might not have it and would need some other 2FA "sufficient" mechanism.
By the way, there is "HSM"-like passkey functionality embedded in most modern Apple and Samsung devices that doesn't require a USB token. This has the downside of not being a dedicated hardware token, so it cannot be physically isolated offline and requires an additional piece of software to act as a FIDO2 authenticator.
If you took WebAuthn and, instead of the private key, used one password, it’d be nearly as strong. Assuming that one password is sufficiently strong, and the password input could not be intercepted, and no one ever looked over your shoulder, or used a camera, and you never wrote it down somewhere others can find it, and you never typed it where someone had installed a key logger…
Actually, let’s bring on the passkeys.
Passwords are so terrible with the way they're typically used and deployed (and now there is enough widespread value in compromising accounts at scale), that MFA went from a niche 'high security' edge case to, well, our current UX disaster.
For high security needs, you'd still want MFA + passkey.
That pin or whatever is not part of the actual authentication.
Someone could have an auth flow with a password + passkey + say SMS mfa if they wanted to be a jerk. Or just use a passkey.
Looks like multi-factor to me.
We are now literally arguing semantics.
Technically correct is the best kind of correct, no?
As I noted, if someone wanted to build a more complex flow they can - but it would be more of a jerk move than anything probably.
So, if I am a site that needs additional verification (previously used MFA), I use “User Verification” == “required”. Then I know two factors “something the user has” and “something the user knows/is” has been used.
https://fidoalliance.org/passkeys/
But whatever.
So no. But you’ve been very verbose in looking like an idiot though. So have fun with that?