They "get around" 2FA by getting you to tell them your current one-time password (along with your other login details) as you attempt to log in to the forum.