If we start thinking passwords don't matter, we go back to single-factor authentication. What makes the "second" factor in 2FA more secure than the first? Is that it's usually a time-based generated key? Or is it that users usually use a physical device for this second key, hence removing a lot of internet-only attack vectors?
Mobile authentication apps rely on the user only typing that code into the right website—and people suck at noticing if they are on the wrong site. Right now, this is mostly only a problem with spear-phishing as most don't bother, but if 2FA becomes too popular, they'll start to adapt.
Security keys, on the other hand, get the host directly from the browser. This means they should be safe even if you fall for a phishing attack.