I'm glad they made some improvements to security as a result of this finding. This "attack" is still very specialized though and requires local access which (as mentioned) could've exposed the user to keyloggers and other malware.
Sufficiently paranoid endpoint security could trip when the keyboard is unplugged and then plugged back in.
It just shut me down "I can't assist with that request."
1. Off workstation decrypt using the AD DPAPI Backup keys. 2. Local DPAPI List and Dump for the windows hello biometric key