That's been pending for a while, I'll just stop contributing code.
In a CLI, oath lets you calculate a TOTP.
But it's maybe a bit more insecure if you use the same machine.
Lose what exactly? Decent 2FA setups make you confirm you've recorded a set of backup codes somewhere (they often recommend print and store in a safe, I find a secure note in a password manager works well) before activating it.
Furthermore plenty of TOTP applications offer secure backup and syncing features.
So again, what specifically do you think you're going to "lose"?
All of the arguments against 2FA here could be made against requiring passwords longer than 8 characters.
It’s not secure. The fix is easy, effective, and has almost no downsides.