4 pane comic of dolan on the left and spooderman on the right
pane 1 (dolan): cum join opensurce cummunity!
pane 2 (spooderman): shure! how joyn?
pane 3 (dolan): Here discord! (with discord logo)
pane 4 (spooderman with tears in eyes): y u do dis?
They force you to enter your phone number if your IP address is fishy to them, or if your email provider is not popular.
Enforcing two factor because of suspicious indicators isn’t bad on it’s own though, it’s privacy concerns about Discord preceding this which makes it a bad thing in this context.
Using phone numbers as second factor authentication is neither secure, nor is it in good faith. Force the customer to use something more anonymous and secure - like Fido keys or even TOTPs. Sneaking in ways to force the customer to reveal their personal details, in the name of security is a sinister dark pattern.