All of this is valid!
But it would be even more secure if there was an opt-in "I don't want to use my phone as 2FA".
Phone number authentication creates a weakness for anyone who is in a targeted attack.
A motivated attacker can easily bribe/trick a telecom employee, or if physically accessible, swipe the phone itself to read 2FA texts.