Fixed in https://github.com/badbundle/vault-app/pull/655 (merged as 24e67d49), which turns the App Lock Password on in the shipping app on top of the storage work in the sub-issues (#641, #644, #646, #648, #650, #651, #653, #654).
- Encryption: the password encrypts the whole vault on the device (
vault-slots.v1: Argon2id calibrated to about 0.5 s, AES-GCM, and a data key wrapped by a key derived from the password). The password itself is never stored. - Setting it converts the plain store. The setup screen says a forgotten password means erasing and restoring a backup, and shows the last backup. It asks before deleting copies of the vault that were set aside.
- Unlocking takes device authentication, then the password. Wrong attempts wait as iOS's passcode does, counted in the keychain across launches. Every attempt finishes at the same fixed deadline.
- Change and Turn Off need the current password; device authentication alone is never enough (C4). Turning it off keeps the file encrypted with a key on this device, so widgets, QuickType and AutoFill come back. Turning it on again empties them.
- Locking: the vault locks, and its keys go, whenever the app locks. With a password set, it also locks as the device locks, whatever the Require Unlock delay.
- Tests: end-to-end tests run through
AppLockService, the adapter and the real storage services on disk. The app was also checked in the simulator: set, lock, wrong and right password, turn off, then unlock with Face ID alone.