Unpopular opinion: It is negligent to allow users to sign up with vulnerable 2FA methods like, OTP, TOTP, or SMS.

Service providers that don't force use of U2F/WebAuthn, even software emulated, should be partially liable for phishing attacks.


