Fixed in https://github.com/badbundle/vault-app/pull/655 (merged as 24e67d49), which turns the App Lock Password, and with it the duress password, on in the shipping app. Earlier parts:
-
#648 (VAULT-51, merged as 78cd21ba): the duress slots.
-
#652 (merged as 28ce2e15): the Set Duress Password UI.
-
#651 (VAULT-70, merged as 2fd6d3b5): per-vault backup settings.
-
#653 (VAULT-34, merged as 86581f1b): the duress password resets the attempt count exactly as the real one does.
-
Setup: one "Set Duress Password" action on the App Lock Password screen. It looks the same whether or not a duress vault exists, and there's no way to view or remove one (C9). Setting it again replaces the duress vault. A duress password equal to the open vault's App Lock Password is refused.
-
Opening it: enter the duress password at the lock screen. Every vault is one of 16 equal slots in the same fixed-size file, and unlocking finishes at the same deadline, so the two passwords can't be told apart by timing, animation or haptics (C2). Device authentication never picks the vault (C4).
-
Inside the duress vault: the same App Lock Password screen and actions, acting only on that vault's own slot.
-
Everything else follows the open vault: backups, the backup password, auto-backup and the PDF hint are kept in each vault's own payload, so backups from either vault don't reveal the other (C10). Widgets, QuickType and AutoFill show nothing while the password is on.
-
No telemetry, logs or history of which vault opened (C3, C6).