You're moving the goalposts. GP was just explaining why base level phishing has been elevated to a higher difficulty level than without U2F.
The way U2F prevents phishing is by binding auth requests to the requesting origin and generating unique key pairs for each origin, so it doesn't matter if the user is convinced and manually activates the key, the phishing site gains nothing it can use on a different origin—even in real time.
The way U2F prevents phishing is by binding auth requests to the requesting origin and generating unique key pairs for each origin, so it doesn't matter if the user is convinced and manually activates the key, the phishing site gains nothing it can use on a different origin—even in real time.