Done in https://github.com/badbundle/vault-app/pull/650.
VaultPasswordChangeService changes the password, turns it off and turns it back on.
- Each needs the current password, checked as a counted attempt held to the deadline. A duress or other vault's password counts as wrong, the same as at the lock screen.
- Turning it off rewraps the open vault's key with a new keychain device key, D, and journals
turningOff. - Turning it back on rewraps with the new password, journals
turningOn, and deletes D. - Every rekey:
- rotates the data key and reseals the body, so an old password plus an older file copy can't read newer copies, and an old key box can't be spliced onto the new body;
- changes only the open vault's slot, and the other slots stay byte-identical, from a duress vault too;
- is stamped with
VaultDeviceWrapStamper; - counts as in-flight on the session, so
lock()waits for it.
The device key D:
- It's accessible after first unlock, restored with a backup, never synced, and wiped from memory after use.
- In device-key mode the file is readable after first unlock, and the lock file is created to match, so widgets can work (VAULT-50).
- It's in the keychain registry, so an erase removes it.
Recovery:
- Turn-off and turn-on: these are settled by trying D on every slot, both in-process and at launch. On a locked device the journal is kept rather than a failure being cached. While a change is unsettled, a password unlock is refused without counting, unless D opens nothing, in which case it goes ahead.
- Missing device key: the vault gets its own failure screen.
- No vault file and no erase journaled: nothing is deleted unless the wrong-attempt count shows an erase was meant. Otherwise a confirmed "Erase and Start Again" screen is shown.
Documented:
- A device-key vault restored from an unencrypted backup onto a different iPhone can't be opened. This is a residual limit, and turning the password off warns about it.
- Resetting the counter on turn-on is covered in the C4 reasoning.
Tests:
- A crash, and separately a failure, at every file and keychain step, each followed by recovery.
- Old and new passwords afterwards, and data key rotation with a splice check.
- Device-key unlock while locked, lock protection classes, and the rolled-back clock.
- Recovery on a missing vault.
Review: a security review found four should-fixes and six nits. A re-review found one more, an unjournaled erase at launch. All were fixed before merging.
The AppLockPasswordService adapter fill-in, and turning the feature on, come in the VAULT-22 wiring PR.