Use Issuer Label prefix in TOTP URI for MFA to conform to recommendations
When setting up MFA using authenticator app, the QR code you generate does not provide Issuer Label Prefix in the label.
This is not according to TOTP recommendations:
https://github.com/google/google-authenticator/wiki/Key-Uri-Format#issuer
Your format is:
otpauth://totp/<EMAIL-ADRESS>?secret=<SECRET>&issuer=Squarespace&digits=6&period=30
This leads Microsoft Authenticator to use the name <email-domain>, for example "gmail" or "outlook", for the account, as per https://github.com/google/google-authenticator/wiki/Key-Uri-Format#label
If another website implements the same bad QR code format as you, on iOS one of the two will be overwritten, and you will loose access to that site.
Squarespace uses the same bad formatting, so chances of catastrophe is big. (I will also be reaching out to them about this)
Please, change your TOTP URI format to:
otpauth://totp/Box:<EMAIL-ADRESS>?secret=<SECRET>&issuer=Squarespace&digits=6&period=30
data:image/s3,"s3://crabby-images/24219/242190d219ff42a1cdcb54ccdb46abef4bd4719b" alt=""