With every other 2FA I've had to reset today (new phone), the recovery key is only shown at the first or second step. Some sites made me re-enter the recovery key to confirm I had it saved. LBC is the only one out of several exchanges I've loaded today that shows the recovery key after 2FA is enabled.
Yeah, I agree that if your machine is compromised - screen and key logging etc - then it doesn't matter if that secret only shows up for 2 seconds. You're done for, anyway.
But displaying the recovery key on the very same screen that allows you to disable 2FA is just plain dumb, since it means anyone with physical access can disable 2FA, without knowing your login details.
To me there seems to be something very wrong with this scenario:
"In order to reduce security on your account, you will need to prove you have the secret."
"By the way, the secret is XYZ."
Once you've proven your device has accepted the key (by inputting the 6 digit signature) there should be no need to show the recovery key again.