The fact Apple uses SMS for 2FA tells you everything you need to know: it's pure security theater.
New logins to iCloud etc always pop up on my MacBook / iPhone with a map image showing me where the request came from and if I want to allow it, o my then can I get the code.
No idea what this article is on about.