It’s Cybersecurity Awareness Month! Join our interactive training session, or learn about security and AI from 1Password experts.
Forum Discussion
maratm
10 months agoNew Contributor
1Password OTP app for Apple Watch
I’m not sure if this qualifies as a feature suggestion or an entirely new app idea, but I wanted to share it regardless. Considering AgileBits’ expertise in the field, I wonder if you could develop a...
1P_Dave
Moderator
9 months agoHello maratm! 👋
Thanks for reaching out! Storing your two-factor authentication time-based one-time passwords (TOTP) in 1Password is safe. Without your account password, an attacker is unable to gain access to your login information in 1Password (including the TOTP).
There is some theoretical benefit in having a separate place to store your TOTPs if your thread model includes the compromise your local device. However, a separate app for iOS/watchOS wouldn't help protect you from that threat since you would still be storing 1Password and the separate app on the same iOS/watchOS device. If that is your threat model then I recommend looking into something like a security key (such as a YubiKey) which would provide true two-factor authentication where your password and TOTP are stored on entirely separate devices.
You can read more here: 1Password & 2FA: Is it Safe to Store Passwords and 2FA Codes Together?
-Dave