Currently, the names of the two 2FA methods we offer are presented to the user as TOTP (one-time token) and Web Authentication (WebAuthn). These names are technically correct but difficult for end users to understand. We should rename these to more user-friendly names.
- Rename TOTP to Authenticator app
- Rename WebAuthn to Security key (later, when we support passkeys, we would either rename this to "Security key or passkey", or make passkeys a separate type)