When setting up 2FA with Authy most websites give you a QR code to scan.
Would it be correct to say that you should treat this QR code securely? If this code or a picture of it was leaked there is nothing to stop someone else setting up 2FA on another device without you knowing, is there?