Earlier quoted context omitted.
The second factor isn’t a second device, it’s the TOTP code.
No, factors are supposed to have different qualities, such as: "Something you know"; "something you have"; "something you do"; "something you are [biometrics]"; "somewhere you are [geolocation]". Passwords are in your head - "something you know". TOTP codes are generated by a hardware token - "something you have". If the TOTP codes are crammed into your password manager, then the factors are no longer distinguished b…
The whole point of a fully featured password manager like 1Password or Bitwarden is to rely on it instead of the security of the service you're using. And that implies that you must trust the security of the vault itself.
Of course, each device you have is an additional (an equally dangerous) attack surface. However, most people should be more worried if someone hacks into their devices than their Facebook accounts anyway.