The team from 1password did a nice writeup, when they introduced storing TOTP in their password manager. Gist is: Most people treat TOTP as a second, time based password (multi step authentication) instead of a second factor. If you truly want 2nd factor, you should never sync your passwords to the phone you are using as 2FA, and never use your passwords on the phone you are using as 2FA. So it depends on your own se…
I've always assumed (possibly incorrectly) that my phone is more secure than my desktop.
Hardware token still feel like the safest option, but I also don’t what 8 different token generator in my pocket.