This is legacy software, as you say (and @techcoderx mentioned) these are tricky issues.
I never made a post before, I just ignored this legacy login method (which was more secure in its day than copy pasting keys).
But I felt compelled to look into it and make a post when I felt mistreated for not drinking the koolaid and exclaiming that it was the most safe and secure app in the world, which it is not.