That’s not even an answer to my question. You say “ 1Password has to work on the understanding that it's running on a device that isn't infected”. But I can see no reason why it should not work on the understanding that it could be infected. That’s the reality. Why can’t users have the option to open the app with TFA only? Passwords are redundant. Would be a lot more secure. I’m actually at the point where I’m going to remove any banking details etc and on,y use it for logging into websites that I don’t care about my data being hacked. It’s safer to have my banking details on a piece of paper in a couple of different locations. Or even on a hidden safe app on my phone.