1Password Storing Your OTP Is Not MFA
The Claim Under Test If your password and your TOTP seed live in the same 1Password vault, unlocked by the same master password, you are running two-step verification (2SV), not multi-factor authentication (MFA). Same secret store, same unlock event, same attacker who now has both factors the moment they get one. This isn’t a hot take. It’s already worked out, published, and ignored, largely because PCI DSS Requirement 8.3 only mandates two factors from two categories, not factor independence or phishing resistance, and most cyber insurance underwriting still treats SMS OTP as an acceptable floor for standard users, even as carriers increasingly downgrade or reject it for privileged accounts. It’s really the same reason why faxing in the USA is considered acceptable for patient health data: HIPAA’s Security Rule requires reasonable and appropriate administrative, technical, and physical safeguards for transmitting e-PHI, not a specific transmission technology, so fax was never excluded and never got re-evaluated once better options existed. Not because either is safe or secure: because it’s legacy knowledge enshrined in permanance. The compliance bar and the security bar diverged years ago for MFA and 2SV; the industry kept building to the compliance bar. ...