@brandon isn't a public key with passphrase 2FA? It requires something you have (your private key) and something you know (the passphrase)

@arielcostas Having an auth code being needed to be typed in addition would mean that an attacker, even with a keylogger, would have a very small time frame to be able to sniff and use your credentials, I believe.

