2fa – A two-factor authentication agent
rsc.io
rsc.io
In order to get access to my account you'd need to know my 1Password master password (which is only in my head) in order to access anything that requires MFA/2FA. If someone hacks Amazon, Coinbase, Twitter, Dropbox, Google, or any other place and somehow figures out my password, they still can't log into my accounts.
Now in the case that one of those services gets hacked and they get access to more than user credentials e.g. all of the data/metadata; Then you're right, having MFA/2FA is useless.
- Password is for them
- TOTP is for meHowever, if your password was stolen from a breached site (or something of the like), your 2fa token, even from 1Password, would still be a second factor.
If you're using 1Password, and you're considering having 1Password manage your TOTP secrets, just skip TOTP. Turn up the complexity on your passwords if that makes you feel better.
I don't think TOTP is dumb; I think you should use it, but only let the keys touch your phone, never your computer.
Is it enough to run the TOTPs through the Google Authenticator on my phone (alongside 1Password on the same device)? I'm unclear on what kind of separation is "useful" separation and looking for the "right" way to set this up.