Hacker News new | ask | show | jobs
by RedTeamPT 894 days ago
Yes, it requires an attacker in a powerful position but it does not require physical access. Any program that runs in the user's session (without any special privileges) could have autonomously retrieved the biometric key and decrypted the vault without user interaction and without Bitwarden running.
1 comments

They mentioned not wanting to use keyloggers which would be their standard approach.