Biometric key is stored in Windows Credential Manager, accessible to other local unprivileged processes

https://hackerone.com/reports/1874155

6 points · 1 comments · view on lemmy.world

1 Comments

Yeah2206@infosec.pub · 1 pts · 3y

This appears to be a problem with window's security model. Not only BW has this problem, 1P has this problem as well, and presumably other password managers that allow such convenience too. The only way is not to persist the encryption key/password/secret across app restart.

See