

I guess if the affected users are keeping their phone and TFA method you could target their phone numbers to try to intercept new codes, although that’s not doable at scale.
Having phone numbers associated to accounts out in public is pretty bad in general, though.
I cut Steam some slack because they were early to that particular party, so they got grandfathered in. Plus the QR signin is fairly useful (not that they couldn’t do it regardless, but still).
Their app is pretty ancient, can be kinda buggy and it’s not great overall, though.