It's not about the user, it's about the attacker. If your account has something worth bothering with, SMS 2FA is a way for an attacker to tell support "yes, I own the phone number, I just forgot the password", which gets the account transferred to the attacker more easily. It's a tradeoff between that and a keylogger meaning game over, but, really, how hard is it to implement TOTP?
> I think the author also fails to mention techniques for detecting account hijacking - Facebook and google for example both look at IP addresses and user agent strings, probably along with other factors, to detect unusual account activity.
That's a very good point, but those are more high-effort functions and only allow detection after the fact, rather than prevention. They're definitely great to have, but I wanted to show two simple features that can help your users' security greatly while being easy to implement.