Removing 2 factor authentication should require authentication from the factor you are removing (And send a notification email). This would make it much more secure and prevent someone who gained illegitimate access to an accounts dashboard from further compromising the account.