trackslash
VAULT-60 P2

Decide whether Delete All Data should also remove the backup password

0
All issues

Description

Follow-up from VAULT-17 (#610).

Today: "Delete All Data" in the Danger Zone (deleteVault()) only clears the item store and the AutoFill store. The backup password, its derived key in the keychain, and the "backup password is set" record all survive it. They stay consistent with each other, and since VAULT-29 (#618) the Danger Zone sheet tells the user the backup password is kept.

To decide:

  • Should Delete All Data also remove the backup password and its record?
    • A device that has been wiped of its vault still holds the key that decrypts its old backups.
    • On the other hand, keeping it lets the user restore a backup straight away.
  • How this interacts with the app lock password (VAULT-22) and with erasing after failed attempts (VAULT-34, which removes the backup password per docs/on-device-encryption.md).
  • Check the change against MANIFESTO.md: C4, C6, and C10 for backups.

This is a Danger Zone change, so the sheet's wording and its snapshot tests need updating to match.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

3
Bradley

Fixed in https://github.com/badbundle/vault-app/pull/666 (merged as 0bea27c1).

  • What's deleted: Delete All Data now also removes the open vault's backup password and the record that it's set. For the plain store that's the keychain's; for an encrypted vault it's the vault's own, so a duress vault only removes its own. Removing never reads the password, so it never asks to authenticate.
  • If something fails: removing the password and clearing AutoFill are each tried whether or not the other fails, and deleting again finishes whatever didn't.
  • Auto-backup: it keeps its configuration and pauses until a new backup password is set.
  • Danger Zone:
    • "Your backup password" is now under Deleted from this device.
    • The overview says to know your backup password before deleting, since restoring will need it.
    • The confirmation says the password goes too.
  • Docs: docs/on-device-encryption.md and the CHANGELOG are updated.
  • Tests: new store, open-vault-settings and data-model tests; the Danger Zone snapshots are re-recorded.
Bradley

Decision (Bradley, 2026-09-27): remove it. Delete All Data also deletes the backup password and its "is set" record, so an old backup needs its password to restore.

Auto-backup's configuration stays: it's still listed as kept, and auto-backup pauses until a new backup password is set. Building it now.

Bradley

Needs your judgement: I've left this open and not changed anything.

Removing the backup password would reverse a choice that's recorded twice:

  • docs/on-device-encryption.md (VAULT-70) says: "Deleting a vault's data, or importing over it, keeps them, as it does the plain store's."
  • The Danger Zone sheet (#618) lists "Your backup password" under Kept.

What keeping it means today (checked in the code):

  • After Delete All Data, Restore passes the kept key to the import (BackupImportFlowViewModel → BackupImportFlowState.passwordProvided), so an old backup decrypts without anyone typing the backup password.
  • The only gate left is Face ID or the passcode, and MANIFESTO C4 says that isn't a gate against coercion.
  • So someone who has the device and any backup can bring back a wiped vault. With auto-backup on, the backups sit in a folder the device can reach.
  • Erasing after 10 wrong passwords (VAULT-34/52) already deletes the key, for this reason.

What removing it costs:

  • Restoring straight after a wipe needs the backup password typed in, and anyone who has forgotten it loses their old backups.
  • Auto-backup would stop until a new password is set. Its folder and file list would stay unless we also clear them, as the erase does.
  • The Danger Zone wording, its snapshots and the design doc all change.

My recommendation: remove it. Delete All Data would then clear the backup password, its "is set" record and the auto-backup configuration, the same as erase step 3 does for the vault that's open (a duress vault only clears its own). "Kept" would then only list your settings.

If you reply with a decision, I'll build it as its own PR.