trackslash
VAULT-34 P2

Erase the vault after too many wrong app lock passwords

0
All issues

Description

Building on the app lock password (VAULT-22), add an option to erase the vault after 10 wrong passwords in a row, like iOS's Erase Data. It's off by default, and turning it on or off requires the app lock password.

Counting attempts:

  • Keep the count somewhere that survives relaunching the app, such as the keychain, so force-quitting doesn't reset it.
  • The escalating delay from VAULT-22 still applies.
  • Decide whether to warn before the last few attempts. Showing the attempts left helps the owner but also tells an attacker.

What gets erased:

  • Everything Delete All Data removes, plus the app lock password and any duress vault.
  • If VAULT-26 goes ahead, destroying the wrapped data key erases everything instantly.

Duress vault (VAULT-23): the duress password counts as correct, and it resets the counter exactly as the real password does. Otherwise the counter would reveal the duress vault (MANIFESTO.md C2).

Tests: unit tests for counting, resetting (including by the duress password) and erasing, using injected storage.

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Fixed in https://github.com/badbundle/vault-app/pull/653 (merged as 86581f1b).

  • The setting: "Erase Vault After 10 Failed Passwords" in the App Lock Password sheet, off by default. It needs the current App Lock Password to turn on or off.
  • A plain device setting: any vault's own App Lock Password turns it on or off for every vault, a duress vault's included. Turning the password off or back on turns it off. The design doc's "Consequences to accept" records that someone with the duress password can turn it off. The token design that let only the owning vault turn it off was dropped, because it revealed which vault had turned it on.
  • At the lock screen, the 10th wrong password in a row erases every vault before answering, and the app opens a fresh, empty vault with no message (C6). There's no attempts-left display, and an erase that's due is checked before every attempt, the same way whether erasing is on or off (C2).
  • Settings and AutoFill never try the attempt that would be the 10th. They send the user to the lock screen, so only the app erases.
  • A right attempt that's thrown away (app locked or task cancelled mid-attempt) still resets the count.

The app starts using the real password service in #655 (VAULT-22).