I've become somewhat familiar with the concept and management of two factor authentication. Many suggestions for using it point to using a third party tool such as Google Authenticator.
However, what are some of the security concerns with a simpler 'home brew' approach, such as: first requiring a username/password, then once that's authenticated to open a second form requiring a specific piece of information sent to the person's email (and/or providing a QR code scheme, and/or SMS message)?