From a corporate standpoint, I don't want people using their personal devices for SMS OTP (2fa) because then if they leave, are disgruntled or get tragically hit by a bus I am locked out of a potentially important service/account. I had this happen on three accounts in the past year where one took me 3 days to recover the ability to access it, another I never could recover and we had to work around it and a third that was absolutely critical but took close to two weeks all said (lots of waiting). That is insane, and all because people used their own personal devices (or similar) for SMS 2fa.
There are other devices you can use, and some enterprises do use hardware keys in addition to the password which works well and the more sensitive the system the more inconvenience people will tolerate and understand.
For me it boils down to 1Password works good for a reasonable price which helps startups and small companies. I also don't think using 1Password is just a tool and you still need a good password refresh cycle and to stop reuse etc. This way if a backup at 1Password was somehow compromised or stored improperly at your company or at 1Password at least you'd be insulated better.
It definitely does provide a single point of access that if compromised in a way which bypasses all their security a lot of companies will be hurting.
Wait...I've seen two ways for services to handle multiple users from a client using the same account.
1. A company using the service gets a single user login for their account. That login is shared by all of the employees who use the service.
2. A company using the service starts out with a single user login for the account. That login is meant to only be used to administer the account. The administrator can create more user logins for the account, usually with reduced privileges. Each employee is given a separate login of their own, with just the privileges needed to do their job.
I don't think I've seen a #1 that uses 2FA. I assumed that was because it could then easily run into the problem you describe.
With #2 there is no problem using 2FA, or with each user using their own device for 2FA. The only account you have make sure won't be lost if someone gets hit by a bus is the administrator account.
Did you run into a service using approach #1 but that used SMS OTP?
And if you squint a little it's still a 'thing you have' since the vault is something you have to have access to so you can generate the constantly changing 2FA token. It's just a bit easier, in theory, to access than a hardware token or an SMS endpoint.
Hover (domain registrar) supports 2FA via TOTP or SMS, but it does not support granting multiple users access to manage a single set of domain names.
I suppose sharing the TOTP key along with the account credentials is better than dealing with the issues created by SMS, but it's still not great.
Essentially my example is the same you pointed out though, for the generic admin account you created you will need to use it to administrate the other users etc. What we do is store that admin account in 1Password with 2fa turned on for it and that way it is never locked to a user with 2fa on their personal device.
For a little more detail too, we will setup sub account for automated systems which have restricted permission (and likely use ssh/key pairs to login for automation). However, when you need to update something about these accounts many times you have to login as them and make a change, so in that case again we store the password and 2fa in 1Password so the team can handle that quickly and isn't stuck because one person left.
I am always open to other ideas though if you think I am missing other options.
Ultimately in this case you are protected from MITM attacks and basic forms of keylogging.
To use 1password on a new device, you need a "secret key" that is provided to you when you create your account which serves as a basic form of 2FA for your whole account. Not a perfect system, but it is not as simple as just getting your password and having access to everything.
So, while I think it storing storing your passwords beside your OTP generator isn't great, if both are locked behind another factor of authentication, you have mitigated that risk significantly.
1password requires more than just a password to access. You need the encryption key. It acts nicely for that purpose.
2fa is unnecessary if you're generating 20 character passwords uniquely for every site.
The best security is like the best camera. There is no better camera than the one you actually use. This is why cell phone cameras are the best. This is why 1password is the best, because it is security you always use and always keep safe.
1. Attacker needs access to the physical device of the account holder if they know the credentials.
2. Otherwise, they need to know credentials + secret key on a new device.
3. You can set up Google Auth to access the account in the first place, which can have its own separate 2fa (this is what we do)
see problem solved, no need to debate how single or two factor a thing is and you can just focus on the attack vectors it actually still solves for, objectively
yes the password vault is a single point of failure if someone knows your vault password or key logs it.