so you mentioned the security revolves around "trusted devices". what would the cotter login experience be like for someone who locks down their browser? i.e., blocks cookies, resists fingerprinting, etc.?
The trusted device works with mobile apps, and it works by generating cryptographic keys and store in the device's secure storage. It doesn't involve the browser to identify trusted devices.
(Trusted device would work with browsers in the future when WebAuthn is more widely adopted. https://webauthn.io/)