Using a phone as a login credential is risky from a reliability point of view. At least with passwords and security questions you can (in theory) have 100% dependable access to them anywhere in the world if you memorize them, back them up, or put them on an encrypted USB flash drive or in an encrypted cloud location.
You can't do that with a phone. You can't duplicate your SIM card. If your phone is lost, broken, stolen, or your service is cut off or unavailable for whatever reason, you're screwed. At least with passwords, security questions, or hardware tokens (of which you can have several), you maintain reliable access no matter what if you've made backups.
You can't duplicate your SIM, but your phone carrier can. In some countries, this involves them checking your government-issued ID in person, which is handy for Google as a way to outsource the ID-checking requirements.
The issue is that they don't discriminate between carriers that perform good identity checking and those that don't.
(Reliability is actually well-addressed by Google - they offer this as a supplement to the other forms of verification they provide.)
You can't do that with a phone. You can't duplicate your SIM card. If your phone is lost, broken, stolen, or your service is cut off or unavailable for whatever reason, you're screwed. At least with passwords, security questions, or hardware tokens (of which you can have several), you maintain reliable access no matter what if you've made backups.