The real word is very unperfect.
[0]https://breakdev.org/evilginx-2-next-generation-of-phishing-...
The important thing here is that you only enter the secret once. It’s different from a password which is reused by design.
I’m going to reconsider why I’m using 2FA and go all U2F or remove it entirely.
You just saved me a ton of hassle next time I swap phones. Cheers.
User creates a strong password in 1Password when signing up for a service. The password is used only for this service. The service stores all usernames and passwords in plaintext. These credentials are compromised without the service knowing. If I'm using 1Password's TOTP then, I think, an attacker is prevented from logging into the service with my credentials. If I'm not using 1Password's TOTP then the attacker can login to the service.
Plus, some buerocrat can tick the 2FA box.
Not to mention the simplest: type in password from 1Password on phone on public browser. Accidentally save password.
Passive interception is not the only possibility. How many password dumps show up each year? Having TOTP enabled, regardless of where it is stored, helps mitigate that threat unless the password that is leaked can also access whatever is storing your TOTP secrets. But if you're using a password manager and reusing passwords, I don't know what to tell you.
Personally I use a TOTP implementation that lets me move the backing store as a file. It's not stored in my password manager, but it's available to me should I need to change phones. That seems like the best of all worlds.
All TOTP devices must store the symmetric key, yes. 1Password goes a step further and provides a UI to allow the user to simply copy the symmetric key out of the login record à la a password.
TOTP clients that make opinionated design decisions prohibiting a user from getting at the symmetric key are correct implementations.
That said, if one wants to mandate 2FA for one’s users, TOTP is not the right choice, given it allows users to do the wrong thing.
I never said it ultimately defends ordinary users, just that it reduces the chances because it requires a more sophisticated attack.
PS - Telling people they are "wrong" isn't convincing, and is downright condescending. Thanks for that.