Comment by eterm
That's how you turn 2fa into single factor authentication ( The ID ).
GitHub is such a large attack vector for the whole planet, that I understand their stance.
GitHub support a "recovery code" more secure than government ID. Print it out, store on USB, store on QR, etc, and stick it in at least one secure safe.