Quote Originally Posted by Seleni View Post
That.. sounds pretty dangerous. The longer the window the more likely that those phishing sites would get hold of the victims’ accounts, which defeats the part of the point of having 2FA.
Absolutely, although this is only a problem when users copy/paste links and give their information out without actually checking if they're official... Maybe SE had enough of people of falling for this hence the made it only a very short window.

Quote Originally Posted by Seleni View Post
I actually switched from the SE’s own app to Microsoft’s Authenticator in hopes of a shorter window, because SE’s own one felt pretty long.
i can't remember how long the SE official app was for their OTP, but anything based on Google Authenticator's OTP system is in 30 second intervals so using another client doesn't make any difference as they're all still generating 30 second codes.