Btw, all U2F services allow you to fall back to phone 2FA if you're on an unsupported device.
Especially the button, which makes it very hard for a remote attacker to get anything from the U2F token.
How many apps are on your phone? How secure is the software stack? Kernel? Hardware? Drivers? If android, how good is your manufacturer + cell provider at distributing the latest updates? Can you prove that an app can't see the screen and send a touch event?
Also generally it's faster to hit the single button on a U2F widget than it is to do anything with a smartphone.
>Well, of course there are always tradeoffs. The biggest one right now is that Google Chrome is the only major browser that supports U2F.
>Because it requires browser support to act as an intermediary between the website and the security key, you can only use it if the browser supports it.
>Mobile is also an issue, as they don't have USB ports!
>Some YubiKeys support U2F via wireless NFC, but support for this in mobile phones is very limited at the moment.