In Denmark there's something called NemID [1], which is basically just a credit-card sized piece of plastic with a bunch of 6-digit one-time passwords on it. It's very accessible, maybe not as secure as U2F, but definitely more secure than SMS.
It ought to be possible for the tech community at large to come up with solutions like this that are better than SMS, but still accessible, just as the push-to-approve 2FA mentioned in the OP.
If official websites (tax, banks, etc...) start to use app 2FA, people with only a mobile phone will have to use, what, physical mail ? Or will they have to go to buildings in person ?
I agree that the more secure the better, but we mustn’t stop thinking of a big part of population that can not afford smartphones (or key or whatever). Same problem for non technical persons.
Alternatively there are a number of desktop based 2FA clients:
- Authy - GAuth - JAuth - WinAuth
To suddenly arm a bunch of people with a new authentication paradigm like hardware keys would just result in a lot of people losing them and then having to go through the establishment's reauthentication channels anyways, which are the weakest link in these systems. And the influx of people needing account resets further degrades the security of the channel the same way you stop asking to see IDs when customers are paying with credit during the lunch rush.
It's not a free lunch.