TGX-Android / Telegram-X

The main repository of Telegram X — official alternative Telegram client for Android.
https://play.google.com/store/apps/details?id=org.thunderdog.challegram
GNU General Public License v3.0
3.39k stars 532 forks source link

Fingerprint is useless on Report #211

Closed EDM115 closed 2 years ago

EDM115 commented 2 years ago

Hey,
I seriously wonder why you include the hex dump of the Fingerprint when an user copy the Report Details
when people share it (either on support group or here), it may lead to security issues
I guess you don't need it, even for testing the app/reproduce issues :) (it would barely come from a specific fingerprint)
That said, have a good day ❤️

vkryl commented 2 years ago

Fingerprint allows filtering out reports from re-signed APKs. Having it in the Report Details doesn't lead to any security issues.

EDM115 commented 2 years ago

oh, so no link to the device fingerprint scanner ?

vkryl commented 2 years ago

No. Moreover, apps don't have an access to the biometrics data (unless they're exploiting some device or system vulnerabilities, which is certainly not Telegram X case).

EDM115 commented 2 years ago

oh sorry then
the "fingerprint" name on the report isn't very explicit
then, users like me may misunderstood it 😅