Read above. Skeptical, misunderstood the threat/risk surface, lack of coherent adoption of modern NIST expectations, focussed on the one story they know, which is the password manager keys are at risk if the machine is compromised.
Thanks! Super useful
TL;DR: TFA doesn't know what a threat model is and complains that security is not perfect when security can never be perfect