Something you have + something you know are multiple factors.
There should still be a password. If there isn't, then it's single factor auth.
Also, SAASPASS looks really interesting. Thanks for sharing. Going to take a much deeper look into this now.
EDIT: Nope, change of plans. The account recovery flow depends on SMS, which isn't safe given how easy SIM-jacking is: https://saaspass.com/how-to-recover-saaspass-id-account/
So now the password isn't in the computer at all and can't be stolen from it.
For example to sign into the web site for my bank account I need to enter a PIN into a chiclet keypad device they gave me, it spits out a one-time code and I type that into the web site. You can't steal the PIN from my PC, even if you have some kind of super zero day exploit and co-operation from the OS vendor, because the PIN gets typed into a separate device that doesn't even have a USB connector. You might as well try to use the PC to steal cash out of my wallet.
The parent's whole point was that this service doesn't have a master password. Nope, instead it has a 4 digit PIN and SMS as it's base flow, with security as an optional extra.
A password manager shouldn't need to be caveated to be recommended. It's too important for that.
only if enabled. Just like any password manager out there.