Play services is how Google delivers many Android updates now so that all users can get security updates without waiting for the device vendor to publish it for each device.
Storing passwords and 2FA in one place only protects you against password reuse, password leaks, and some more common threats that the large majority of people should be looking out for.
It is still a lot better than no 2FA, and more than sufficient for the average person.
For someone looking to improve their security a bit more and for someone with a "don't trust anyone" model, having a separate 2FA app has it's advantages. It protects them against unencrypted password DB leaks, security vulnerabilities in the password manager, or any intentional security threat induced by the developer of the password manager
A PWA can have the familiar "Sign in with google" button now, which pops up a similar page as shown in the article, but with accounts.google.com in the fake URL bar.
This looks a lot like a Oauth request, where you are redirected to sign-in. You check the URL and enter the creds, with the assumption that you are using "Sign in with Microsoft" to login to the site since this is how that login flow works
In the end, they hold the keys irrespective of how many algorithms they wrap on top.
I do not feel it is any different from Google Chat, Twitter DMs, etc. They do have a lot of censorship resistant and anti-MITM attack features in between, but they hold the keys by default
I use it for convenience and amazing features, not for security!
DCMA would not work here since they are hosting a copy of it for archival purposes, and not claiming copyright. The original public URL is included.
Archive.org does respect robots.txt tho. It is possible to completely delete a site's history on Archive.org by modifying the robots.txt (at least in the past, not sure if that is the case now)