Fixed in https://github.com/badbundle/vault-app/pull/653 (merged as 86581f1b).
- The setting: "Erase Vault After 10 Failed Passwords" in the App Lock Password sheet, off by default. It needs the current App Lock Password to turn on or off.
- A plain device setting: any vault's own App Lock Password turns it on or off for every vault, a duress vault's included. Turning the password off or back on turns it off. The design doc's "Consequences to accept" records that someone with the duress password can turn it off. The token design that let only the owning vault turn it off was dropped, because it revealed which vault had turned it on.
- At the lock screen, the 10th wrong password in a row erases every vault before answering, and the app opens a fresh, empty vault with no message (C6). There's no attempts-left display, and an erase that's due is checked before every attempt, the same way whether erasing is on or off (C2).
- Settings and AutoFill never try the attempt that would be the 10th. They send the user to the lock screen, so only the app erases.
- A right attempt that's thrown away (app locked or task cancelled mid-attempt) still resets the count.
The app starts using the real password service in #655 (VAULT-22).