PayPal absolutely didn´t get the essence of security keys. They just want to say "PayPal supports security keys", just because it sounds fashionable. Supporting one security key and forcing the user to adopt TOTP as backup (or even worse, use the security key as backup to TOTP) is like closing a window for security reasons and let the one beside it open.
... View more