Ah, I stand corrected, I forgot about trusted hardware based 2FA.
Still, it doesn't allow SMS or email based 2FA as far as I can tell, since that involves a trusted server and doesn't mean anything in a trustless model where the server owner could just add a bypass.