Comment by _karie_
5 months ago
Any malware or LLM with user-level filesystem access can attack the outdated KDF [1] and/or wait for Firefox to be running with an unlocked credential store and read the decrypted passwords from Firefox's process memory.
Isn't it game over anyway once you have an adversary on your system capable of reading process memory?
[dead]