You can already enable both methods, and Google Authenticator will be a fallback on devices that don't accept YubiKey.
I will try that again as that's not what I recall happening. Also: I'd really prefer LPA with push-support (but without it's own SMS fallback)
If email verification is a concern, set up a dedicated security email address and keep the information completely separate from LastPass.
If I have to store a password outside of LastPass that I can never loose: why wouldn't it just be the LastPass password.
What is the scenario where I'm immune to losing this special email password but not immune to losing the LastPass master password (which, if I don't lose, I will never need recovery for).
Further: Please let me know which email client can be 100% guaranteed immune to any form of compromise... because otherwise all we are doing is moving from one way to compromise LastPass (a compromise affecting LastPass itself) to two (either LastPass or email).