Especially since big tech is steaming ahead to mandating passkeys that only they are allowed to control/backup. Not long until all governments could intercept your passwords to all services.
That is exactly the question. I took a look and we presented some of our findings at DEF CON 34. There are paths to decrypting e2ee secrets without the passcode, some of these paths are considered vulnerabilities and have received patches (CVE-2026-28864).