Something true to be said about back in the day learning that a good security practice is to not have your direct route all provided by the same vendor (or even version of firmware/software)
Example: Cisco ASA XYA firewall, Cisco Switches, Cisco USC appliance, Cisco VoIP appliance...
More likely to be an easier target if a compromised function on the Firewall happens to also work on every other device all the way to the end-data...
Having your Google account (Gmail, Drive, etc.) also be the password/TOTP/etc. "vault" which is synced? Similar shortcoming in security it would seem from my perspective. Your Google account compromised now possibly opens up your entire Google portfolio to the attacker.
@Kim_Nilsson "that's why they should use passkeys" - I can here it now lol