Skip to content

android(fix): don't log proximity keys (IRK / encryption key) - #810

Open
QuerTeal wants to merge 1 commit into
librepods-org:android/rewritefrom
QuerTeal:fix/dont-log-proximity-keys
Open

QuerTeal wants to merge 1 commit into
librepods-org:android/rewritefrom
QuerTeal:fix/dont-log-proximity-keys

Conversation

@QuerTeal

Copy link
Copy Markdown

Summary

MagicKeysResponsePacket.parse() logged every parsed key as hex at debug level. On an unknown key type it logged the raw key again.

These keys are sensitive:

  • The IRK resolves the AirPods' rotating BLE addresses.
  • The encryption key decrypts their proximity advertisements.

Together they let anyone holding them track the AirPods. Logcat output is exactly what users paste into bug reports, as the issue templates ask for logs.

With this change, only the key type and length are logged.

Testing

On-device logcat now shows Parsed Proximity Key: Type: 1, Length: 16 and Type: 4, Length: 16, without key material.

🤖 Generated with Claude Code

MagicKeysResponsePacket logged every parsed key (IRK and encryption key)
as hex at debug level, and the raw key again on an unknown key type.
These keys allow resolving the AirPods' random BLE addresses and
decrypting their advertisements (i.e. tracking them), and logcat output
is what users attach to bug reports. Log only the key type and length.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant