Technically email becomes the skeleton key regardless. And that is dependent upon at least one third party: domain registrars. And possibly email providers too.
Though the post does have a good point on that non-email auth providers add more risk to the equation.
Though the post does have a good point on that non-email auth providers add more risk to the equation.