As you might know, some providers send the auth code via SMS instead of using a 2FA application. In theory, if you're planning to attack a single person, it's shockingly easy to call the provider and gain access to the SIM card. This technique is called "Social Engineering" and is actually pretty effective.
Google Authenticator and competitors use an encryption key which is shared with the device via the QR code you're scanning at initial setup. Therefore, the code is unique and device-bound, so there is no way for an attacker to gain access to it (unless he gets access to your device).
acá toca guardar la clave secreta de cada sitio para la configuración de 2FA.