trackslash
VAULT-50 P2

Encryption 11: bring widgets, AutoFill and QuickType back after the password is turned off

0
Sub-issue of VAULT-22 P2 Add an optional password to the app lock

Description

Sub-issue 11 of the on-device encryption design (VAULT-26, docs/on-device-encryption.md).

Why it's needed: once the password is turned off, the vault stays in the encrypted file, with its key wrapped by a device key. Widgets, AutoFill and QuickType must work again, as they do for a vault that never had a password.

The change:

  • A keychain access group, so the extensions can use the device key.
  • A reader in the extensions for the encrypted file.

Decided: this is in scope, so turning the password off doesn't leave a lasting compromise.

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Done in https://github.com/badbundle/vault-app/pull/654.

Access mode: a single VaultAccessMode (plain, deviceKey, password, unavailable) decides what every surface may do. Any mid-change state (encrypting, erasing, turning off or on) is unavailable.

With the password turned off (device-key mode):

  • Widgets:
    • They open the file with the device key afresh for every read. These show-only opens don't lock, stamp or write.
    • The small widget's HOTP tap opens the app. Incrementing inside the widget would run out of memory on a device.
  • AutoFill:
    • It asks for device authentication only, never a password, and opens with the device key only after authentication.
    • It checks the mode before and after opening. A new VaultAccessGuard re-checks the mode on every read and write of a vault an extension opened, so an open sheet can't keep showing codes after the password is turned on, or after an erase.
    • Leaving the sheet locks the vault. Coming back re-checks.
  • QuickType:
    • Refilled when the password is turned off, and emptied when it's turned on. Both steps are journaled (syncingSystemSurfaces / clearingSystemSurfaces) and finished at launch after a crash.
    • It's skipped when Vault isn't an AutoFill provider. Widgets reload either way.

Also: the attempt counter's flock retries with LOCK_NB up to a timeout. Plain-mode AutoFill also locks immediately now (C7).

Documented: the design doc's device-key column, and residual limit 11: widget memory with a 16 MiB+ file, HOTP increments sent to the app, and AutoFill's stricter memory check.

Tests:

  • The full mode × transition table.
  • Mode flips between prepares, between authentication and display, during the open, and as a save starts.
  • Widget .unavailable, show-only opens leaving nothing behind, and QuickType locking after a read.

Review: a security review found one blocker (an open AutoFill sheet ignored the password being turned on or an erase, and opened with the device key before authentication) and two should-fixes. All were fixed and re-reviewed.