The article mentions Yubikeys, but it doesn't mention that Yubikeys implement U2F.
The article reports that Google internally switched from TOTP, but doesn't report what Google switched to: U2F.
The article describes, in some detail, how TOTP and SMS two-factor authentication can be phished, but doesn't describe a two-factor authentication method that is quite a bit harder to phish: U2F.
There is a pattern here, and it is puzzling, to say the least.
EDIT: Changed "phish-proof" to a more realistic adjective.