Would it be a viable and simple solution to only enter 6-digit codes into the specific website that requested it?
Isn't this the same thing as BAD asking, let us know the code i.e. password that GOOD gave you? Why would one be inclined to give BAD (i.e. someone else) this info?