IIRC the telephone authentication is not used if the machine has already been used to log into the account. Since the company gave away the username and password, all that would remain is to steal the cookie used to identify a machine that has already logged in.
That could be done with an XSS attack using JavaScript to access the cookie and divert it.
I considered doing this but would have needed to sign up for an account and that required giving a credit card which I didn't want to do. Well done to the people who made it work.