Earlier quoted context omitted.
U2F is great but everything is better than SMS.
Except SMS is better than nothing, right? Yes it's flawed. But it's a harder attack than simple password auth. An attacker has to to target an individual and know their phone number, and be able to spoof their phone.
At its worst, it opens up a social engineering / customer support "lol lost my phone" attack vector that didn't exist before.
SMS 2FA can be defeated by hijacking someone's number. Happened to me. One day I opened my Macbook and saw the "A new iPhone has been activated for your iCloud account". They had access to my number for hours after I called up my carrier.