What I miss in the U2F tokens is a small display that would show transaction details which is approved.
Imagine you have a malware on your PC; it can send another transaction than the one you see in the browser, while the URL would still match. Having transaction summary on the token would be the last verification point where can still spot something is wrong.