This is what I thought. I keep telling people they don't exclusively own their passwords / security tokens once they give it to a site. Salted hashes to obscure the pw don't even matter since the admin could also bypass that. Tanks for the validation.
I'm sure site admins could just clear the 2FA field if they wanted. Would they? IDK, probably not unless they had good reason.
Could someone steal your session information and disable your 2FA with that? Yeah, but I doubt they did, you'd have to have your system compromised or some kind of cross site scripting.