> I think you don't get security.
I charge $500/hr for security consulting, 1 week minimums, and am fully booked for months out. I have 20 years in security experience. I'd say I "get it".
I specialize in security UX.
Don't mistake my absolute position on what is secure vs what is usable and what will be used. In general I am a critic of U2F.
All the problems you have stated are real, and you are correct, however the way to overcome them is NOT to have the device keep/use the secret "insecurely". Watch Apple's blackhat talk from last year for some insight into the problem and a usability-friendly yet still secure approach.
It's a hard problem, not one that is going to be solved here on HN discussion.