I assume that in addition to the QR code there would be a link that would trigger an intent to open the authentication app with the necessary data. At least on Android that's how it could work.
A minor problem is that auth app has to return back to the browser with a new link which the browser may not be able to open within the original login tab.
I don't think that is the case. After the auth app communicates with the server you just need to click the login button on the original page. I don't think the auth app needs to load a specific url.
A mirror and a front facing camera :-)
Wouldn't you need at least 2 mirrors to correct the image?
A front facing camera already flips the image so that the user sees what they usually see when they look in a mirror. So one mirror would end up being right. Except when you open the camera app, the mobile site is no longer displaying the QR code.