zecwalletco / zecwallet-mobile

Zecwallet Android and iOS apps
10 stars 11 forks source link

Privacy Issue: Unable to toggle between Memo Download settings #71

Open kowalabearhugs opened 2 years ago

kowalabearhugs commented 2 years ago

Unable to toggle between Memo Download settings. 'Wallet' is selected by default and I am unable to choose 'None' or 'All'.

IMO 'None' should be the default as 'Wallet' leaks tx information about the user/wallet to the lightwallet server.

ZecWallet Lite 1.7.8 Android 12

zancas commented 2 years ago

Hi! Is this issue still affecting you. We've tested on Android 11 and there's not an obvious problem. Are you still unable to select None and All?

kowalabearhugs commented 2 years ago

Nothing has changed on my end, so yes, the issue persists. Unable to select None or All. There are others who have confirmed this is an issue on both the zcash forums and though a post I made on Twitter. Something is amiss.

I believe the issue existed for me on Android 11, but I am currently running Android 12 and do no intend to downgrade.

Do the developers not view the default settings, that leak tx metadata to the lightwallet server, as a privacy issue?

zancas commented 2 years ago

It seems like an issue to me. I'd like to figure out how to reproduce it. I will see if I can find someone with an Android 12 test device.

kowalabearhugs commented 2 years ago

I appreciate your feedback and willingness to sort this out. Apologies if I wasn't clear regarding the issue per se.

It's certainly a problem that the settings cannot be changed, but the underlying fault is that the default is to download memos and share that metadata with the lightwallet server. The default setting for a privacy-centric wallet should be that users must manually opt-in to that type of sharing.

zancas commented 2 years ago

I see your point!

We have an issue tracking this concern here:

https://github.com/zingolabs/zecwallet-mobile/issues/55