I can accept 2FA being disabled without requiring the code. It is more concerning that the 2FA secret is shown on the account details page. I believe the best practice adopted by Google / Dropbox is to not reveal the secret once enabled, and to use a new secret if 2FA was disabled then reenabled.
Hey, thanks for answering my questions, and I certainly hope you support LTC in the future. You only have to read
this thread to see how the lack of a secure & trusted online wallet for LTC is an opportunity for scammers and hurts the cryptocurrency community.
2FA code is now hidden entirely after it has been enabled, and a new secret is generated every time it is disabled.
UI on smaller screens also fixed. You'll need to do a hard refresh.