> the reality we live in is that many financial institutions still only support phone-based 2FA
I believe that's exactly the point the grandparent comment was addressing when they said "we stop using SIM for authentication". The "we" wasn't necessarily referring users, but to services and providers currently using SIM 2FA in their products.
I totally agree with you. I am not blaming Cloudflare here, they are trying to create workarounds and patch holes around the lack of proper 2FA from those services and providers. But the real goal is imo those services and providers implementing proper 2FA.