Forum Discussion
about how watchtower works
@sl91911 1Password is different to other password managers because the secret key and secure remote password protocol protect you from a lot of the attacks that 2FA helps prevent. However, it is still useful.
1. Yes. 2FA protects against the case where an attacker knows your master password and secret key, but doesn't have a copy of your 1Password database.
2. If you want to use a hardware security key for 2FA then you will first need to setup an authenticator app because not all platforms support security keys. The authenticator app can act as your backup if you lose your key. Alternatively set-up multiple security keys and store them separately. As a fall-back you can disable 2FA from any previously authorised 1Password app.
3. No. 2FA is only required to authorise download of the 1Password database to a new device. Install the desktop app and the lock state will be synchronised between the desktop app and all instances of the browser extension.