People who design TFA systems should be required to actually use them
my biggest complaint with them right now: SMS or emailed auth code in the form of digits, which you can't actually copy-paste into the form because they do every digit as its own separate text input an then implement their own focus handoff thing
completely unnecessary use of javascript and it's absolute shit for accessibility. also macOS and iOS try to autofill it from recent messages and it also fails to actually enter all the digits