Depends on how you define two factor. To me it is using a different device than the device you authenticate with and unless you compromise that device you cannot authenticate any other way.
The way it deals with compromised private keys is that you can store the list of websites you authenticated to on a central location and run a reset of all your authentications on all websites in one go from there. But then it relies on a third party.
I don't pretend that this is the ultimate solution (nor am I aware that there is an ultimate solution) but it does seem more secure and practical than anything else I have seen so far. I am sure you can make more secure but less practical and of course less secure and more practical.