So my vault (on mobile device) is encrypted with my Master Password. Without the Master Password, the decryption cannot happen.
There is an option to enable Fingerprint Authentication on the mobile devices. Obviously that is only done after you have provided the Master Password, and your vault is now “unlocked” (decrypted) locally on the device.
However, even if I restart the mobile device, I can log back in with just the fingerprint. So how can it decrypt my vault after restart with just the fingerprint?
Does the “unlocked” vault mean it is stored unencrypted on device’s permanent (not RAM) storage? Is the fingerprint is just a security-theater, as someone can bypass the app and access the (unencrypted) vault directly on device storage?