Either make me create a password and then let me into my account or let me use my phone number/email to verify. It’s becoming too much to get into every day stuff. If I have biometrics on there is zero reason for anything else.
Basically the current security system is overdoing it. I suggest getting rid of passwords all together OR only requiring one or the other. Like it I forget my password or I forget my phone I can use the other but JFC its a hassle.
Then you need to know 2 different codes.
They would need to hack the server password database or your password app AND have physical access to your device.
It is the same concept as using biometric + TOTP or password.
Something you have, something you know, something you are: those are the 3 general “factors”