> It protects against phishing
Not so much. U2F proves only that the user tapped the device when asked to do so.
You still have to trust your browser and your entire desktop that the tap will be used to log in to the service you are browsing instead of e.g. quietly logging to your home banking.
To prevent "tap hijacking" we need a display on the U2F key to show the URL/service you are really authenticating to.