Ironically, yesterday my wife couldn't find her phone while we were at a restaurant. Is it at home? Well, let's try this. Google it, go to http://android.com/find Ah, but it only shows devices logged into my account. Well, let's log into hers. Which required 2FA from... her device. Sooo useful.
Yeah, this seems like such an incredibly obvious oversight. Like... I know how it goes with fuzzy requirements, but who didn't nail down the acceptance criteria that the user should be able to trigger Find My Phone without 2FA.
Hackers were able to steal private photos of half of Hollywood in 2014 because someone at Apple decided that 2FA is not needed for one particular iCloud function.