Isn't 2FA considered dangerous now? We've seen how susceptible it can be to social engineering. On a related note, I noticed that my Windows Phone displays text message notifications even when it's locked... So adding a PIN doesn't prevent an attacker from doing 2FA if they have access to my phone.
2FA with, say, a hardware token or even a phone app is generally pretty good.