Would be nice to use some kind of U2F effectively storing the secrets on a hardware key.
We are looking into using WebAuthn. I haven't fully grasped what's possible there yet, but some integration with your existing devices (like auth with your biometrics on the phone) is definitely coming.