Frankly, a secure password alone, with no second factor, is "drastically" better than a secure password with ability to change that password by SMS, as is frequently the case (a quarter of the time, per that research). So set up LastPass or 1Password for your aunt.
As for "protects her from 95% of the attacks she is likely to face", that's a number that doesn't jive with my experiences as CTO of the second largest bank in the world.
Your claim is "Because most customers, most of the time, are not under a targeted or even semi-targeted attack."
On the contrary, most customers are under automated attacks, and SMS plus password leaks lets that takeover be fully automated.