OH, I see, thanks. The password and TOTP secret are separate, but you're suggesting they may likely both be stored in the same place such that a breach could give attacker access to both. Tell me if I don't have it right.
It occurs to me that I know how to reset my password most places I log in to, but I actually have no idea how to reset the TOTP secret.