I don't think TFA works well for securing mobile devices, because the entire premise is that it sends the second authentication token to your mobile device.
Even then, it would be better than the status quo — you'd need physical access to my phone to access my Apple account, preventing the kind of remote attacks that were made famous recently.
Ideally it would be a yubikey or something not attached to your phone anyway.