Passwords don’t work because people can’t remember very much. Password generators don’t work because they have to store the key somewhere. Might as well just authenticate with the encryption key. Encryption keys often get lost, so they need to be stored in the cloud, accessible with a password, which brings us back to the first problem, but adds another point of exploit, or ‘lawful intercept’. Phone number second factor doesn’t work because that can be stolen or transferred, and the same device is probably used for password reset. Authenticator apps don’t work because devices can be stolen, and they require a password anyway to transfer to a new device. Biometrics don’t work because they can be cloned, or used on an incapacitated person, and in the case of phone biometrics, they can be overridden with a pin. FiDO devices don’t work because they can be lost or stolen and used by someone else. Social recovery doesn’t work because of moral hazard and probably the only people you trust that much are not particularly savvy with security around this kind of thing. Practically in an app, they would also have to authenticate in some technical manner, so this cascades.
What have I missed?