Threat model
This page summarizes the public threat model in the vaultkeepr-public repository. The full document covers the open-source SDK packages and Solidity contracts as used by VaultKeepR clients; client applications live in a private repository.
Assets and how they are protected
Section titled “Assets and how they are protected”| Asset | Protection | Where it lives |
|---|---|---|
| Vault plaintext | XChaCha20-Poly1305 AEAD, key derived client-side | Never leaves the device unencrypted |
| Master password | Argon2id (t=3, m=64 MiB, p=4), never transmitted or stored | User’s memory only |
| Vault encryption key | Derived client-side, session copies in memory only | Device memory |
| Encrypted vault snapshots | Content-addressed ciphertext on IPFS / S3-compatible storage | By CID |
| Recovery fragments | Shamir splitting, encrypted fragments | IPFS + on-chain pointers |
| Vault location pointers | Public by design; they reference ciphertext, not plaintext | VaultKeeperCidRegistry on Base L2 |
| Legacy instructions | Time-locked on-chain, encrypted beneficiary payloads | VaultKeeperLegacy on Base L2 |
Adversaries
Section titled “Adversaries”- A passive network observer sees ciphertext blobs, CIDs, and traffic metadata. It learns that a vault exists, when it changes, and how big it is. It learns nothing about contents.
- A storage operator (IPFS gateway, S3 host) holds ciphertext and cannot decrypt it. It can withhold, corrupt, or censor data. That is an availability threat, not a confidentiality one; content addressing makes tampering detectable.
- An on-chain analyst reads the public registries on Base: writes, fragment pointers, legacy schedules, timestamps, sender addresses. Activity is linkable.
- A malicious client or dependency (a compromised SDK build, a supply-chain injection) could exfiltrate keys. Mitigations include pinned
@noble/*primitives, a phishing blocklist inlined at build time, a redacting logger, and CI on every push. - The server operator of the commercial service only ever handles ciphertext; compromising the backend does not decrypt vaults.
- An attacker with physical access or malware on your device is outside cryptographic scope.
Accepted limitations
Section titled “Accepted limitations”Read these before trusting the product with anything critical.
- Metadata is not protected. Timing, size, frequency, CID access patterns on gateways, and on-chain activity are observable. An adversary can correlate vault updates with real-world events.
- A compromised endpoint is a compromised vault. Keyloggers, memory scrapers, and screen capture defeat any password manager’s client-side crypto. The threat model ends at the OS boundary.
- Master password strength is the user’s risk. Argon2id raises offline attack costs but cannot rescue a weak password. The bundled entropy estimator informs; it does not enforce.
- Availability depends on storage economics. IPFS gateways and pinning services can fail or disappear. Recovery fragments mitigate this, but they require you to hold the threshold.
- On-chain records are permanent and public. Registry entries and legacy schedules cannot be hidden or removed once written. Treat chain addresses as pseudonymous, not anonymous.
- Legacy windows are visible on-chain. Beneficiary timing leaks even though beneficiary payloads stay encrypted.
Source files
Section titled “Source files”- docs/THREAT_MODEL.md
- SECURITY_ASSESSMENT.md — likelihood and impact ratings per risk