Earlier quoted context omitted.
> you get the added benefit of being able to store 2FA settings Don't do this. If you use a password manager with all the benefits this entails (long, random passwords, each only used for a single site), the only benefit 2FA really gives you is if your password manager is compromised somehow. If your second factor is in your password manager, you're screwed. I use Authy with a long, secure password printed on a piece…
> Don't do this. On the other hand, do do this, but be aware of the tradeoffs. I hate telling people not to do something. Most people just end up not turning 2FA on at all. My approach has converted many people from "one password reused everywhere, at best with variations" to KeepassXC unique passwords everywhere + 2FA and I classify that as a big win. The biggest benefit of TOTP 2FA isn't the "second factor" part, i…
But it emphatically does not protect against keylogging, anyone who can install a keylogger on your computer can grab your password DB and your master password. This is exactly the scenario where you need actual 2FA.
Anyway, broader point: yes, it's a tradeoff, but the kind of people who needs explaining why a password manager is a good idea, do not understand enough to make an informed decision about these tradeoffs. And so, the responsible advice is to not use it.
I do know enough to understand these tradeoffs, and my conclusion is to keep password management and 2FA strictly seperate.