Is it all possible to truly need 2FA on every sign-on on mobile?
I have 2FA enabled for my account. I know that 2FA is only used to protect transport of the vault from cloud<>device, that's fine. What I want is to actually NEED 2fa to access any vault data on my mobile. The data in the cloud is at least protected by secret key + passphrase, data on my mobile isn't as the secret key is already on it.
I know 1P keeps a local cache and as people have pointed out, just asking for 2fa to grant access would be security theater. So obviously the app would have to remove that local cache when logging out of 1P (or being logged out due to time-out/idle/lock). And yes I of course realize that would make offline use impossible :) That's a trade-off a user can then make for themselves. I consider mobiles at sufficient risk of loss/stolen that I prefer to enforce actual two-factor input to get to my passwords.
1Password Version: 8.10.6
Extension Version: Not Provided
OS Version: Android 11
Browser:_ Chrome
Referrer: forum-search:https://1password.community/search?Search=two%20factor
