To get past the strong password you'd basically need a keylogger, and if you have that, then you'd also get the google password?
2fa is not a one time password. it uses a key that changes roughly every 10 seconds. so they would have to guess your very very long password and then also they would have to guess at precisely the right time the correct code to enter to bypass the 2fa auth.
Its like having 2 locks on your front door. one has a key for the main lock it unlocks it everytime. the other lock needs a new key every 10 seconds. every 10 seconds the lock is switched and u are given a new key.
jsut enable it bro dont be an idiot.
Just googled the google authenticator, and I thought it's just the google account's password you need to type in addition to exchange password, but I thought wrong and apparently it sends the code to a phone instead. I just suspect I'm far more likely to lose/brick my phone than install a keylogger without me knowing, so my funds are actually safer without the 2fa.
Use Authy, you can have your codes restore if you lose your phone.