bypassed 2 factory authentication is done in many way most common way is to intercept the http connection all of social media are use https this can be done with intercept & wireshark to track the pack then you need decrypt the packet as fast as possible.
some other way is hijacking the victim session then reverse the model control to detect the otp code.
well also another way is to change your current activity to the victim location via vpn or proxy some of the social media & website not ask if the user login in same ip or near location.
last but not less do your activity in public wifi near your victim like coffe or bar to hit him don't ask for otp codr.
as i say there's too many ways depending on your factory & your attack