This is true for all 2FA methods but not for FIDO security keys. With FIDO, the hostname of the site you're browsing is signed in the assertion, therefore the attacker -even with automation- can't reuse it on the target site.
This is why FIDO claims protection against phishing.
What the author says is that the attacker, when you're using a FIDO security key, can simply say it's not working and force the user to switch to a different 2FA method, therefore in the end phishing the user.
This is why FIDO claims protection against phishing.
What the author says is that the attacker, when you're using a FIDO security key, can simply say it's not working and force the user to switch to a different 2FA method, therefore in the end phishing the user.