I personally am fine with this.

  • ReversalHatchery@beehaw.org
    link
    fedilink
    arrow-up
    4
    ·
    1 year ago

    First of all, that they are totally unnecessary for twitch to be able to provide 2fa authentication.

    Other than that, their app has tracker components, all secret keys are stored in the cloud, who knows whether that’s encrypted, but on your phone’s storage surely not, if yours is rooted you can just view it in a file manager and copy it to a normal code generator app.
    Generally they support standard TOTP code generation, but for twitch they are using some weird shit that generates 8 long numbers (instead of the standard 6), of which the middle 2 is the same so they drop one of them, and then also codes expire in third the time as it is normally.