If the attacker got access to your 1Password account, then yes, you're screwed.
However, if your password was stolen from a breached site (or something of the like), your 2fa token, even from 1Password, would still be a second factor.
However, if your password was stolen from a breached site (or something of the like), your 2fa token, even from 1Password, would still be a second factor.
If you're using 1Password, and you're considering having 1Password manage your TOTP secrets, just skip TOTP. Turn up the complexity on your passwords if that makes you feel better.
I don't think TOTP is dumb; I think you should use it, but only let the keys touch your phone, never your computer.
Is it enough to run the TOTPs through the Google Authenticator on my phone (alongside 1Password on the same device)? I'm unclear on what kind of separation is "useful" separation and looking for the "right" way to set this up.