Windows Credentials manager has Bitwardens credentials in it...What? Why? Is this a security issue?!?

Offline access is specifically a supported and expected feature. The above scheme no longer allows offline access. So this could be an additional security feature, but would have to be opt-in.

It would be much better to have two-layer encryption to local database at rest anyway.

I agree. It just has not been implemented so far.

1 Like