This is quite important as a single security key is a single point of failure; using a weaker backup option weakens the whole MFA. Witness the recent attacks on Cisco and Cloudflare: Cisco got owned as their staff were using OTPs, Cloudflare didn't as they use security keys *only*.
This is quite important as a single security key is a single point of failure; using a weaker backup option weakens the whole MFA. Witness the recent attacks on Cisco and Cloudflare: Cisco got owned as their staff were using OTPs, Cloudflare didn't as they use security keys *only*.