For my use case, yes BLE is a hard requirement.
Their example of hijacking a BLE keyboard to get passwords seems a bit farcical. I would love to see a PoC of that attack. The API has been available in Chrome for quite a while. I don't think it has been a large attack vector.