Got a call from an FBI agent about
@vaultaire_app last week.
They told me they found someone using the app. They suspected he used Capture to photograph classified material. When they asked him to open his vault, they believe he may have triggered a duress vault and wiped everything.
They called me hoping I could help recover or access it.
I explained that I simply couldn’t.
Vaultaire was deliberately designed without a master key, backdoor, or recovery mechanism. I have no way to access a user’s vault. I can’t even tell whether he triggered the duress vault. There are no breadcrumbs for me to follow.
The agent was fuming. He essentially asked: why would you build an app like this?
I told him I believe in the right to individual privacy. I can’t stop someone from committing a crime. But that shouldn’t require everyone else to give up their privacy.
He asked me to come to the field office to explain more. I told him to call my lawyer. Never heard back.
I obviously can’t verify what happened on the device or comment beyond what I was told.
But that was a pretty surreal way to have Vaultaire’s security model tested in the real world.
Was debating sharing this, but my lawyer says it’s ok 😬