>the attack already assumes access to the workstation of the victim
I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.
I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.
A far-fetched scenario? yes. But if it can happen, it will happen.
This is why I totally understand when Apple or MS go overzealous with encryption or T2 or secure boot. Despite "people like us" complaining about it.
It's different from trying to pry open an encrypted hard disk from a laptop or something similar.
You probably won't even know that coworker you trust is compromised and attacked you this way.