This is a good distinction and absolutely right. The problem comes when people substitute good passwords for 2fa resets via phone. The problem with that is that the majority of usage now comes from the phone, so it's not really a second factor if you lose your phone. It's a complex problem that depends on the situation and really too complex to make a matrix of when it's ok for your average Joe. Passwords suck, and we still use them, because as a general rule, it's the best thing we have.