Not sure I follow "You'd be better off without 2FA" (unless you're counting the use of the number for advertising) - it's weak, but it doesn't introduce additional vulnerabilities.
And IIRC at the time Twitter didn't offer any other 2FA mechanisms.
And IIRC at the time Twitter didn't offer any other 2FA mechanisms.