TOTP isn't an ideal second factor, for most of the reasons above (combined with poor adherence to the standard, meaning that only the most basic subset of features tend to work). But is is still a second factor, unless you can do HMACs in your head :-)
But the typical totp-in-password-manager setup is missing the other factor, there is nothing you know in such setup.
But yes, I agree. I keep my TOTP on my phone (I use Aegis) and my password manager on my desktop computer.
Ok. Thanks for sharing your thoughts.
Personally, I think storing your password and TOTP secret is worthwhile, but it ultimately depends on your threat model.
If your threat model is someone walking up to your unlocked desktop and unlocked password manager, then it's not very effective. That being said, I believe a determined enough attacker will always win -- just be more annoying to pwn than others and you will sift out the majority of attackers, imo.
But, if your threat model is that a website you use suffers a data breach and your username/password hashes are stolen, you have an extra line of defense with that second factor. This pretty much happens or will happen to everyone with online accounts at some point.
So my long-winded answer is that I do still consider it two factor auth, and I do think it's worthwhile -- but all effective security should be layered with extra defenses when possible.
EDIT: fixed some grammar, added some extra context.
The risk with same-device (or same-manager TOTP) isn't necessarily in a physical adversary (who's going to win anyways), but in a digital adversary who can run code (or read files) on one device but not several. That's one of the main reasons users are encouraged to use physical factors or, lacking that, an on-device factor that requires some kind of OS-mediated privileged interaction.
Yes, correct.
> So my long-winded answer is that I do still consider it two factor auth.
Ok, thanks for sharing your thoughts.
While PCI DSS 4.0 says nothing specific about TOTP, it on page 171 also has this phrase about certificates:
"A digital certificate is a valid option for “something you have” if it is unique for a particular user".
So it is not an unreasonable analogy to claim that the TOTP seed stored in a desktop application is also "something that you have", as not having it prevents you e.g. from logging in from your friend's laptop.
Oh, ok. This is very convincing. Thanks for sharing.
If you have two different passwords, aren't they still only one factor (knowledge)?
> specially if you have...
You mean to say in case the password and the TOTP seed are stored in the same password manager, then it is no longer 2FA?