The argument was not that cheap smartphones cannot handle email apps (or such); but these phones can only have so many things and definitely no expectation to have hardware based security features.
You probably don't need hardware security features. OS-based software U2F would probably be a step up (prevents sim-jacking, but physical access to the phone is possibly more vulnerable)