The author cites two "flaws":
1. Your phone is offline sometimes.
Twitter has a backup code mechanism that covers this case. They talk about it, right in the post.
2. An attacker can send verification requests that look exactly like yours.
The sole use case for this mechanism is to verify login attempts by the phone's owner in real-time. If a verification request comes in and you're not actually trying to log into Twitter, or if you see more than one, you know you're being attacked.
It's true if you share a login among multiple coworkers then you're vulnerable to being tricked. But that's a bad practice to begin with, and this 2-factor system is still a massive improvement in security even for that scenario.