A password that gives nothing away.
Set a second password on your vault. Entering it opens an empty decoy and quietly clears the real one. An unlock forced under pressure looks exactly like a normal one.
This is an Android feature today. iPhone has the full signing surface but not duress yet; it is next on the list.
Three passwords, one shape.
The lock screen cannot be read from the outside. Whatever you type, the app behaves the same way up to the moment it decides what to open.
Your real password
Opens your vault as normal. Identities, recipients and notes, exactly where you left them.
Your duress password
Opens a fresh, empty vault and clears the real one on the way in. Nothing on screen marks it as different.
A wrong password
Fails the way any wrong password fails. Same screen, same timing, no hint that a duress password even exists.
Built so the three cannot be told apart.
- Each password derives a key. The password is run through
scryptto derive a key-encryption key. Real and duress derive different ones, and a wrong password derives one that unwraps nothing. - Same path, same timing. The unlock does the same work whichever password it is handed, so there is no faster or slower answer to watch for.
- The decoy is real. The duress password bootstraps a genuine empty vault. It is not a fake screen; it is a working vault with nothing in it, and its password becomes the decoy's own password.
- Destructive by design. Opening the decoy clears the real vault. There is no hidden switch back, because a switch back would be the tell.
- Password-only afterward. Once the decoy is in place biometric unlock is torn down, so the vault opens with the password alone. No fingerprint prompt survives to contradict the story.
The duress unlock destroys the real vault. That is the point, but it means anything you cannot afford to lose should live in a backup somewhere else. Treat duress as a safeguard, not storage.
Unlocking with a password or PIN, without any biometric, works on its own too. See the security page for the full design.
What it does, and what it doesn't.
Plausible deniability is a real tool with real limits. Here is the honest version.
- A clean unlock under coercion. If you are made to open the app, the duress password shows an empty vault and leaves nothing to find.
- No tell. Nothing on the device flags that a duress password was used or that a real vault ever existed in that slot.
- Local-only. Like everything else in AgePony, this happens on the device. There is no server that knows any of it.
- Protection from off-device copies. If someone already imaged your storage before the duress unlock, that copy is outside AgePony's reach.
- Cover for other traces. Backups, screenshots, files you exported, or another app's records can still exist. Duress clears the AgePony vault, not your whole device.
- A way back. The real vault is gone after a duress unlock. This is deliberate, and it is why a backup matters.
Set it up on Android.
Free, open source, no accounts. iPhone gets duress next.
Walkthrough: set a duress password.