Earlier quoted context omitted.
Do not store your 2FA codes in 1Password. It turns your second factor into the same one as your password. I was storing backup codes in 1P before I realized that I was putting all my eggs in one proverbial basket.
Not quite - if someone steals your 1Password (or equivalent) database with TOTP seeds in, they need to crack the password on that, then have full access to everything. If they get the password from the other end (e.g. the site you log into), they can probably log into that specific site (they will have the TOTP seed), but not anything else. In general, there are more attackers looking at the site end than at the clie…
It's pretty obvious why this changed, however, it is a major increase in exposure and a terrible change overall. It is discussed in [1] and mostly the answers aren't very satisfying as demonstrated in [2].
[1] https://discussions.agilebits.com/discussion/101560/secure-m...
[2] https://discussions.agilebits.com/discussion/101551/article-...