Fixed in https://github.com/badbundle/vault-app/pull/669 (merged as 2c0eaf48).
What Delete All Data does now:
- It empties the open vault, keeping its slot and the App Lock Password that opens it.
- In the same locked, verified write, it fills every other slot with fresh random bytes (
VaultSlotFile.randomizeSlots(except:)). So the real vault and every duress vault go, whichever vault it's done from, or none do. - Every other slot changes whether or not it held a vault, and the file keeps its size, so nothing shows whether others existed.
Edge cases:
- It saves even when the open vault is already empty, where a change normally skips the save.
- After a conflict with the AutoFill extension, it works the delete out again and still destroys the others.
FAQ: a new page, "What's a duress password?", explains:
- what a duress password is, and that you can have several, one inside another;
- what can still give a duress vault away, including the real vault's backups;
- how to start a duress vault again without Delete All Data: make a new one from the vault above it.
Tests: new real-file tests delete from the real vault and from a duress vault, check that empty slots change too, and cover an already-empty vault and the conflict retry. The docs and CHANGELOG are updated.