@czue yeah you're right on the 2FA. however i do see passwordless implementations just leak the login code in the email which pops up even on locked screens, which presumably password managers are immune to