This is awesome. Truly a modern-day way of securing boxes.
Of course, it makes it more of a hassle to maintain a machine, and you might get temporarily locked out if their VOIP line or whatever goes down, but the same could be said about fingerprint readers. I personally try to avoid those mechanisms if at all possible, but it's great that someone is offering this as a simple service. Really cool!
I disagree. Having a 2FA that sometimes (i.e. very rarely, but not never) goes down is still safer than no 2FA, and I can never afford to be locked out of my server.
However, I could also see the opposite case being made. And I assume this is precisely why they made it an easy config change, to make it behave however you prefer.
For strictly secondary authentication, it's much more likely that an admin will lock themselves out through local misconfiguration than an attacker will find the mechanism disabled.
Of course, it makes it more of a hassle to maintain a machine, and you might get temporarily locked out if their VOIP line or whatever goes down, but the same could be said about fingerprint readers. I personally try to avoid those mechanisms if at all possible, but it's great that someone is offering this as a simple service. Really cool!