My big goal now is to come up with a better solution for 2FA that works for me and my wife's shared accounts.
My big goal now is to come up with a better solution for 2FA that works for me and my wife's shared accounts.
I understand the idea of putting both factors in one place is odd, but I feel it strikes the right balance between the convenience and security.
This is AKA "one factor", right?
I'm no math wiz but pretty sure that makes it a 1.5 factor
The main threat vector would be, as you mentioned, compromise of the actual password manager.
As far as I can tell, 1Password’s end to end encrypted architecture makes this less probable.
That would reduce the main risks to our actual devices.
TOTP MFA is crap anyway because it has no passcode and it is so trivial to sync and it’s common for people to do so. So in scenarios where people close to you are a risk, or you’re dealing with other peoples data, it’s pretty weak control. It’s great for preventing spray attacks and mitigating some compromise scenarios.
It’s likely members of your household, friends, coworkers have access to shared devices or shared vaults in 1Password. That makes that type of MFA more like 1.5 factor vs 2 factor.
Whether you want to be one bad front-end UI deployment away from both factors being exposed, fair question...
But the shared accounts that are my pain point only offer SMS OTP.
As for shared SMS, look into Google Voice. They automatically forward SMS texts to email as an option. I created a "shared" email account and gave my family access to that.
I did find a way around this, in that I had a real number, added all my 2FA accounts to it, and then ported the number to Google Voice, but this isn't a long term solution. Idk how long Google Voice will stick around, but I have found a couple backup options that are low cost if I need to keep the number long term.
i use 1password's built-in 2FA (TOTP), but only for a couple accounts as i find it unwieldy generally. i'm also keeping an eye on how passkeys develop over time.