All these things have become so essential that it's shocking that it's not regulated like a utility (or even as a right given their systemic imposition).
All these things have become so essential that it's shocking that it's not regulated like a utility (or even as a right given their systemic imposition).
Where it becomes challenging is situations where smart phones truly are required. When I attended college football games last fall, all tickets were e-tickets. You were required to present a QR code on your device or your ticket stored in Apple Wallet or Google Wallet. I ran into the same situation with my local theater's ticketing. You haven't lived until you've witnessed an audience with an average age of 70 try to figure out their tickets on their smartphones when they've never used them for that before nor had any notion that was even POSSIBLE.
You can use client certificates even with IMAP and SMTP.
But can be easily stolen by malware (unless someone adds a client cert OS support? intriguing idea). But so can passkeys stored on the same device, so I don't know.
Long time ago browsers even had a widget to generate client certs natively! But it was removed, probably because of lack of use.
Now expect aunt Lottie to use certificates? Yeah, sure.
I think there are some significant limitations to client certificates as a general-purpose 2FA mechanism.
Reusing the same certificate would make you trivially trackable across the web. You could create a unique certificate for every origin, but you need a way to permanently store the certificate. That becomes a problem if you want to secure them with hardware tokens where storage is limited. Yubikey 5 series can only store a handful of certificates.
Passkeys (i.e. resident FIDO2 keys) aren't intended to be a second factor, they're intended to be the only factor but they also require storage. Yubikey 5 can only store 25 resident keys, for example.
Non-resident FIDO2 keys (previously U2F) are what's traditionally used for 2FA. The hardware token derives key material from its master key and credential ID provided by the browser and the server, so it doesn't require any storage.
When you want to use another browser or reinstall one, just re-enroll the new one. Ten one time recovery keys act as an alternative second factor, just like it's commonly done now.
I'm not saying there aren't any tradeoffs at all, but in my opinion they're minor when compared to OTPs, SMS or Yubikeys. Not nearly enough downsides to explain why no major services supports client certs.
I see you are suffering from something that always happened to me when championing them: they were so unknown that people assumed you meant PGP…sigh.
I so hate this. I have repeatedly seen PDFs containing nothing but a QR code and text like "not valid if printed" - this is truly silly. QR codes were created to form a bridge between the physical and the digital world, exactly so people can print them out. If you want it to be digital-only for some reason, use NFC or Bluetooth or whatever.