No, please do not do this. Two factor authentication should be just that: two separate factors of authenticating yourself. Having them combined in one is the same as one factor.
Said in the reply to the other comment here, but I don’t really self host for security/privacy sake. And in addition to that comment I’d also like to say that I do use a YubiKey when possible for MFA. I’m not a security nut enough to care about TOTP (which kinda sucks anyway) all too much but for important things I do use physical MFA.
No, please do not do this. Two factor authentication should be just that: two separate factors of authenticating yourself. Having them combined in one is the same as one factor.
Said in the reply to the other comment here, but I don’t really self host for security/privacy sake. And in addition to that comment I’d also like to say that I do use a YubiKey when possible for MFA. I’m not a security nut enough to care about TOTP (which kinda sucks anyway) all too much but for important things I do use physical MFA.