trackslash
VAULT-74 P2

Make Delete All Data wipe every vault, not just the open one

0
All issues

Description

Today: Delete All Data empties only the open vault's slot (its items and tags), plus its backup password (VAULT-60) and AutoFill. The other 15 slots in vault-slots.v1 are copied byte for byte. So deleting from the real vault leaves any duress vaults, and deleting from a duress vault leaves the real vault. The Danger Zone still says "Every code, note and recovery phrase on this device".

Decision (Bradley, 2026-09-27): it wipes every vault.

  • Empty the open vault as now, keeping its slot and the App Lock Password that opens it, so it stays a data delete rather than a full reset like the erase.
  • Overwrite every other slot with fresh random bytes, every time, whether or not it held a vault. The result then looks the same whether other vaults existed or not.
  • From a duress vault, this destroys the real vault too. Accepted: it's destruction, not exposure, and it doubles as a quick way to wipe everything under duress.
  • In plain mode there's only one vault, and set-aside vaults already go.

Footgun: someone in a duress vault who only wants to reset that vault would now lose the real vault too. The sheet can't say so without advertising other vaults (C9). The safe way to reset a duress vault is to make a new one from the real vault, which replaces the old one. Say this in the FAQ, not in the Danger Zone.

Also: update docs/on-device-encryption.md ("Delete All Data empties the open vault's slot…"), the Danger Zone's wording if needed, and add tests that every other slot is re-randomized, including slots that held nothing.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Fixed in https://github.com/badbundle/vault-app/pull/669 (merged as 2c0eaf48).

What Delete All Data does now:

  • It empties the open vault, keeping its slot and the App Lock Password that opens it.
  • In the same locked, verified write, it fills every other slot with fresh random bytes (VaultSlotFile.randomizeSlots(except:)). So the real vault and every duress vault go, whichever vault it's done from, or none do.
  • Every other slot changes whether or not it held a vault, and the file keeps its size, so nothing shows whether others existed.

Edge cases:

  • It saves even when the open vault is already empty, where a change normally skips the save.
  • After a conflict with the AutoFill extension, it works the delete out again and still destroys the others.

FAQ: a new page, "What's a duress password?", explains:

  • what a duress password is, and that you can have several, one inside another;
  • what can still give a duress vault away, including the real vault's backups;
  • how to start a duress vault again without Delete All Data: make a new one from the vault above it.

Tests: new real-file tests delete from the real vault and from a duress vault, check that empty slots change too, and cover an already-empty vault and the conflict retry. The docs and CHANGELOG are updated.