can't do a whole lot without also physically stealing my phone.
??? Theres a while bunch of loopholes they can exploit without having access to your phone, here's must one.
https://www.netspi.com/blog/technical/web-application-penetration-testing/why-totp-wont-cut-it/
I do it the way you do it as well but am under no illusion it's bomb proof.