They're better than nothing, but outside of enterprise contexts (e.g., enterprise-managed CAC cards and other hardware tokens), I think expecting 2FA to defeat malware, physical access, etc. is too much.
They're better than nothing, but outside of enterprise contexts (e.g., enterprise-managed CAC cards and other hardware tokens), I think expecting 2FA to defeat malware, physical access, etc. is too much.
Yep, and "using a password manager with a randomly generated password for each site" already mitigates that just as well.
Barring a user using 1Password and still reusing the same password on every site (why are you using 1Password then?) the only use-case I can think of for storing TOTP tokens alongside your password in 1Password is "the service requires me to use TOTP and I don't care about security".
That said, full disclosure, I've kinda got a bone to pick here because I was a long time 1Password user that was forced to switch off when 1Password removed the ability to have multiple vaults because, as they have said on their support forums, "It's called 1Password and our users only want one password." which was a... mind-boggling response from a company that should be focused on security. And this blog post really doesn't instill much more confidence than that response did.
These days I have my passwords in a KeePassX database. I have my TOTP secrets stored in two places--on my phone in an authenticator app where they're on a very secure platform and practically unrecoverable, and in an entirely separate KeePassX database that has nothing in common with my password database. The only time the KeePassX TOTP database is opened is when I set up a new service and want to add my TOTP secret. It's only there to "break glass in case of emergency" and allow me to recover access if my phone were to become unavailable. It's the right balance of risk _for me_, and in most practical sense two _factor_ authentication.
For a single user, they're equivalent in almost every way to just having 5 or 6 folders in one vault, so the "separate vault" distinction is pretty much gone.
Basically, what I want is two separate, independent bank vaults. Opening one should not, in any way, help you open the other. I want to keep my spending money in the main vault, and my stack of gold bars in the other vault that I only open in case of an emergency. That way, the risk of anyone seeing the combination over my shoulder or sneaking in when I've got the vaults open is minimized.
What 1Password gives you is the ability to easily create other vaults, but every time you build a new vault, they put the combination for that vault on a sticky note inside your first vault and give you no way to remove it. The security of your second, third, fourth, etc vaults is irrevocably linked to that of your first vault. All your gold bars are, no matter what you do, forced to always be exactly as secure as your spending money because as soon as someone gets into your spending money they just need to look at your sticky notes and they've got access to everything else.
There's no real security purpose for having a second vault in this system. The only purpose is to more selectively control access to what other people can access (i.e., vault sharing / team features). If you want to make some of your spending money available to your wife but not all of it and not your gold bars, you can build _another_ vault, put some cash in it (and the sticky note in your first vault so you remember how to get in!) and then also give her a sticky note she can stick in her vault with the same combination. Now you can both easily access the shared vault, but she can't access your main vault or your gold bars and you have no way to know what she has in her vault at all.
Things like this and the enforced cloud sync are decisions that weren't in any way a trade-off (the path they chose does not preclude the more secure path). The fact that they keep removing the more secure option regardless really seems like a security company that's more focused on market and revenue growth than security now.
If your use-case aligns with what 1Password is selling, I'm sure they still make a great product.
If sharing's a huge part of what you're looking for, then 1Password or Bitwarden are probably your best options. If it's not and you're comfortable managing your own sync, then I don't think KeepassXC can be beat.
Pretty much the only thing I'll say concretely is Don't. Use. Lastpass. Like, if you've got the option of putting all your passwords in a plain text file on your desktop or in LastPass... pick the plain text file.