The review is done. Detailed notes are kept outside the repo and the tracker, as the disclosure rule asks.
What was checked. Every area listed in the ticket:
- the duress features (C1–C9);
- data at rest;
- App Lock and the App Lock Password;
- backups, exports and transfer (C10);
- system surfaces;
- offline and supply chain;
- cryptography;
- the docs against the code.
Four parallel read-only reviews covered these, and a fifth took the docs. The new tests (VAULT-83) re-checked a good part of it.
Guarantees. docs/security-model.md (#700) lists every promise (G1–G83), with where it's enforced, the test that pins it (or "none") and whether it holds as stated or with a limit. The README and both AGENTS.md link to it.
Fixed, in neutral PRs, each with tests:
- #673, #674, #675, #677, #678, #680, #681, #682, #683, #685;
- #686, #687, #688, #689, #690, #693, #698, and one fix within #699.
Accepted and documented (the design doc's "Consequences to accept" and "Residual limits", and the security model's "Accepted limits"):
- Without an App Lock Password the store is readable and goes into iPhone backups.
- Killphrases match on the whole search as it's typed, only in the app's own search.
- Backups made with one backup password share a salt.
- The per-item key derivation is lighter than the App Lock Password's.
- Some build tools are prebuilt binaries.
- The duress nesting limit.
- Backups now carry the killphrase and passphrase keys.
- Guessing on the device is limited by the waits.
Follow-ups. None filed. Three MANIFESTO wordings don't quite match the code (C2, C6 and an example in C7). Changing the manifesto needs its own MANIFESTO: PR, so that's left to Bradley.
Disclosure. SECURITY.md asks for reports through GitHub's private vulnerability reporting, which is now switched on for the repo, and never in an issue, a PR or this tracker.
Not done hands-on. Data at rest was reviewed from the code: every file, defaults key and keychain item the app writes, with their protection classes. Inspecting a real app container on a device is still worth doing before the next release. So are the device checks in RELEASE.md (Face ID and the passcode, and the AutoFill sheet locking with the device).