You made me check but there is a "birthday" field on the contact form and I can display a "Birthdays" calendar with events for the birthdays of my contacts.
The fact that users have to delete the old Github key from their systems and accept a new one is what could lead to a MITM attack.
If your system doesn't know the public key of an SSH server, when you connect the first time, the SSH client will display a warning and ask you if you accept the server key. An attacker could be between you and Github and if you accept without checking it's the correct key, you would be toast.
On Instagram, when you create an account, you now need to submit a selfie picture while holding a code given to you while registering. For suspicious account, it can even be a video selfie. I know bots are an issue but they should ask for this only when posting/commenting, not for browsing. No way I'll send a picture or video to facebook linked to my email/phone number.
I think asymmetric encryption is not usable for large amount of data, the only thing it is good for is to encrypt a passphrase or a binary signature (like a hash). If you can catch the process of encryption while it is running, it is likely that the passphrase is in memory (or used as a command line argument).
As the sibling comment is saying, I never set up 2FA on my account. When I do, I'm using totp and store backup codes. Apple decided to force 2FA and use security questions as the second factor on my behalf.
On top of this, many companies provide customer support to reset 2FA with an other way to verify who you are.
But I never set up 2FA on my Apple account, security questions were meant to be used as an account recovery procedure if you lost access to your account email. THEY set it up as 2FA and as a result I can't log in. I have accounts on numerous website and this is the first time I'm completeoy lockout. I would gladly send my ID card to Apple but apparently this is not an option.
I'm not in the US, there is no Apple Store near me, only resellers. I never had to answer security questions up to now, and never stored the answers in my password manager. I thought that a reset by email was possible, but apparently not ...
I can reset the password myself, what they won't do is reset the security questions through an email for example. They told me that if I don't have the answers, there is no way to recover my account.
Is there any way you could offer to _buy_ the code from your cofounder ? If he/she believes there is no value in it (hence the pivoting), there shouldn't be any problem.