Can someone explain point #9 in the gist? How’d they know part of the two factor code?
The goal isn't to protect against phishing or social engineering, but against people accidentally approving a sign-in they didn't initiate.
There's a screenshot of what this looks like here: https://gist.github.com/zachlatta/f86317493654b550c689dc6509...