What phishing scenario, and how is TFA completely defeated by it? The article just says "the best defense against phishing is a 'security key'", but doesn't explain why other options like TFA are inadequate.
I didn't say TFA would be the ultimate solution, but that it's likely to be supported by more things that people use (like apple devices..). If you choose a solution that might be technically superior but require people to make major workflow changes, you'll find they won't use it. TFA seems like a good compromise to me, so I'd really like to understand why you think it is not.