[Security Feature] Option to require Yubikey tap, to autofill or view password, within browser extension

There is little or nothing that can be used to protect your secrets if this happens.

The above is identical to another existing feature request (Require 2FA during unlocking process ), you can just vote for that request.

This would be essentially equivalent to the another of the previously mentioned feature requests (Adding Biometric/PIN authentication with Master password re-prompt ), except that you are esking for additional encryption (whereas the Master Password Re-Prompt feature is just an access control function and does not add extra encryption).

So what you’re asking for is to encrypt sensitive information (what exactly — only the passwords and custom hidden fields, or the entire contents of every vault item?) using a Yubikey or biometrics before encrypting a second time with the account encryption key. Thus, after unlocking the vault (which deciphers the contents using the account encryption key), the protected contents would still be encrypted until decrypted using the Yubikey or biometrics.

Perhaps you can flesh out the proposal a bit, and add an update to your top post. I would also suggest changing the feature request topic title to something like “Second Encryption Layer for Passwords Using Yubikey/Biometrics” (to distinguish it from the other, existing feature requests).

What do you mean by “browser extension file”?