You could make the case that "stealing" talent is in terms of targeting hiring people where the training and research costs were footed by someone else.
Then again, as you pointed out, you could also make the case that they weren't properly compensated.
If I'm not mistaken it should be mostly fine as long as you trust the desktop/phone versions of Bitwarden not to send off the (unhashed) key to the server
Just checked, should be available on the self-hosted version as well. [0] And the author of bitwarden_rs seems to be planning to tackle it over the weekend!
I'm not sure I like hardcoded URL's that fetches stuff every time I run a program without good reason. Also, I wouldn't ever trust the program itself to check its integrity. But I digress, it's definitely an interesting project.
What are the pro's and con's of using it instead of the win32 version of OpenSSH? [0]
Edit: [0] is also a much better source than BBC in this case.
[0] https://www.vice.com/en/article/wx5xpx/hackers-steal-data-el...