Earlier quoted context omitted.
Just to add, Twitter's 2FA is "broken" because it only has SMS support. You cannot configure an app and I don't want to give Twitter my phone number.
Even if they supported an app (TOTP Google Authenticator style), wouldn't it be likely for the secrets to have been leaked along with the passwords?
The post also gives a justification for using symmetric encryption, it lets the tokens users enter be shorter.