I had the impression two-factor by SMS was actually fairly doable to get access to, not by snagging phone, but by working wireless operator over.

Sometimes the second factor actually gets treated as an added one factor for password reset, too.

Annoyingly, I'm not really aware of any standard for communicating the auth implementation, and definitely not one that any service actually publishes. Just gotta step through password reset and such manually.