in reply to Tuta

I fully agree, but any MFA is better than no MFA. TOTP through authenticator apps and hardware tokens like Yubikey or Solo are the good practices.
Passwords .. We only see passwords copied or shared (via phishing), not broken by cracking, that takes too much effort anyway. I can't recall password incidents because of brute force attacks, except for stupid breaches of websites, when a password file without decent encryption and a salt is used (like LinkedIn ages ago).