I am absolutely disappointed and appalled at the blatant security issues with both @\Steam and @\WarThunder as they require mobile apps for 2FA. Why the hell are you trying to reinvent the wheel when you're not involved in #InfoSec. It should be standard TOTP or FIDO #sync
@chiefgyk3d what do you expect them to have better security then my bank who uses sms as โ€œ2faโ€.

@chiefgyk3d Throw Blizzard onto that pile too. You can only use their app and nothing else. The only other option is SMS...

Square-Enix did the correct thing (eventually) as they had their own proprietary app for their MMOs #FinalFantasyXI and #FInalFantasyXIV but changed it to allow you to use TOTP in 2021.

You can actually still buy their hardware security token from their website for $15 - https://store.na.square-enix-games.com/en_US/product/564762/square-enix-security-token

SQUARE ENIX [SECURITY TOKEN]

One-Time Passwords are available as a means of further securing your Square Enix account. Users can make use of the freely available Square Enix Software Token (iOS/Android), mobile software authenticators (Google, Microsoft, etc.), or by purchasing this physical security token. Learn more about one-time passwords and how they help secure your account: https://square-enix-games.com/en_US/seaccount/otp

@chiefgyk3d Might there be a reason one would want to drop a piece of code one is in control on someone's mobile device?

@chiefgyk3d Yup, at least with Steam there's been some effort to reverse engineer the format, extract the secret and some password managers like BitWarden support "custom" TOTP generation for Steam.

But they still require the App for changing things like E-Mail or Password, because they confirm this through another signed-in device >.<

@chiefgyk3d This is not a defense, just some fun history fact. Once again Valve fell victim to them implementing things early. Their in app single use codes were there before TOTP apps became popular. And just like with the "steam protocol" - nobody wanted to change it for a long time. And now a new sensation becomes popular - QR code, passwordless login, which they also implemented early.