what about FaceID + pin? that would mean someone would have to know your pin as well as have access to your face. you also wouldn't have to look so paranoid while entering the pin. and pin by itself would be of little value.
The author started off saying how less than 1% of Dropbox users use two-factor authentication. What good is such a scheme when nobody is going to use it?
I think you're right that the number of people who would use such a system is trivial (compared to sales).