Twitch should either remove the requirement to set up SMS 2FA as a stepping stone to setting up software based 2FA, or allow users to remove SMS 2FA after setup. An alternative for backup could be backup keys that users can store safely in a password manager like many other major platforms provide. Offering the option to use software 2FA while requiring that SMS 2FA be in place defeats the purpose of using the software, and leaves accounts just as vulnerable as if they only used SMS 2FA.
Twitch should either remove the requirement to set up SMS 2FA as a stepping stone to setting up software based 2FA, or allow users to remove SMS 2FA after setup. An alternative for backup could be backup keys that users can store safely in a password manager like many other major platforms provide. Offering the option to use software 2FA while requiring that SMS 2FA be in place defeats the purpose of using the software, and leaves accounts just as vulnerable as if they only used SMS 2FA.