It seemed clearly-written and thought-provoking to me; the author doesn't claim that 2FA is a burden, either.
Writing and distributing software should be straightforward so that everyone can participate. And consuming software should be safe so that people and infrastructure are protected. Finding a security model that achieves both should be the goal.
PyPi appear to have walked a reasonable line on this so far, and it's worth considering and discussing what the future could be like.