trackslash
VAULT-22 P2

Add an optional password to the app lock

0
All issues

Description

Building on the device-authentication app lock (VAULT-21), let people set their own app lock password. Once it's set, unlocking the app needs device authentication and then the password.

Vault encryption (decided): the password should encrypt the whole vault on the device, not just gate the UI, but only if that's feasible without compromises. VAULT-26 investigates that and comes first. If it isn't feasible, the vault isn't encrypted and the password only locks the app.

Requirements:

  • Storage: never store the password itself. Use the app's key derivation (VaultKeyDeriver), tuned so that unlocking stays quick.
    • If VAULT-26 goes ahead, the derived key unwraps the vault's data key.
    • Otherwise, store only a verifier and compare it in constant time.
  • Wrong attempts: slow down repeated wrong attempts with an escalating delay.
  • Changing or removing it: require the current password. Device authentication alone isn't enough.
  • Naming: make it clear this is a different password from the backup password.

Forgotten password:

  • Device authentication can't be the way to reset it, because a coerced user can pass it (MANIFESTO.md C4).
  • So the way out is to erase the vault and restore from a backup.
  • Say so plainly when someone sets the password.

Tests:

  • Unit tests for setting, verifying, changing and removing the password, including the attempt delay.
  • Snapshot tests for the password entry, and for setting the password up.

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Fixed in https://github.com/badbundle/vault-app/pull/655 (merged as 24e67d49), which turns the App Lock Password on in the shipping app on top of the storage work in the sub-issues (#641, #644, #646, #648, #650, #651, #653, #654).

  • Encryption: the password encrypts the whole vault on the device (vault-slots.v1: Argon2id calibrated to about 0.5 s, AES-GCM, and a data key wrapped by a key derived from the password). The password itself is never stored.
  • Setting it converts the plain store. The setup screen says a forgotten password means erasing and restoring a backup, and shows the last backup. It asks before deleting copies of the vault that were set aside.
  • Unlocking takes device authentication, then the password. Wrong attempts wait as iOS's passcode does, counted in the keychain across launches. Every attempt finishes at the same fixed deadline.
  • Change and Turn Off need the current password; device authentication alone is never enough (C4). Turning it off keeps the file encrypted with a key on this device, so widgets, QuickType and AutoFill come back. Turning it on again empties them.
  • Locking: the vault locks, and its keys go, whenever the app locks. With a password set, it also locks as the device locks, whatever the Require Unlock delay.
  • Tests: end-to-end tests run through AppLockService, the adapter and the real storage services on disk. The app was also checked in the simulator: set, lock, wrong and right password, turn off, then unlock with Face ID alone.