It's not suprising that Duo Security is interested in exposing this flaw in their 2FA flow, since their product is a somewhat better 2FA solution. I've evaluated their solution for my project, but ultimately settled with MePIN which offered similar security at lower price.