As far as I'm concerned it's not only user-hostile, but deliberately malicious. Moreover, there's no excuse for services to use phone numbers for 2FA.
In a sense they are used as a kind of "hashcash" to raise the cost of fake accounts.
You can improve privacy by one-way transforming the number in a way your systems can't undo (eg hmac with a key in hsm configured for enc only, with rate limiting), but naively you lose agility and some useful capability (eg ban accounts with numbers from this range).
So store two hashes, one being the whole number, another being the number excluding the last 2 digits. These aren’t difficult problems to solve. The bigger issue is that they’re not revenue generating solutions, but rather the opposite.
this is the reason why all megacorp mobile apps and every other free flashlight/calculator/alarm app require access to your contact list.
Discord allows you to enable phone number verification at a per-admin level basis; and it is done to reduce spam and bots. You can't just pretend the problem doesn't exist.
i’m a privacy junkie, but we can’t just handwave those away and pretend they don’t exist.
Just kidding but this happened to me when I used IRC back in around 1993-1994. For some reason I would respond anyway and would get banned for a time.
This is a solved problem, but these things create friction for the user. And friction is the opposite of what modern tech says you want to provide to your user.
Get them to endlessly scroll, comment thoughtlessly.