From 172d44459c8f32926552b158583bb729db20ad03 Mon Sep 17 00:00:00 2001 From: QuerTeal <11648267+QuerTeal@users.noreply.github.com> Date: Mon, 28 Sep 2026 00:52:33 +0900 Subject: [PATCH] android(fix): don't log proximity keys MagicKeysResponsePacket logged every parsed key (IRK and encryption key) as hex at debug level, and the raw key again on an unknown key type. These keys allow resolving the AirPods' random BLE addresses and decrypting their advertisements (i.e. tracking them), and logcat output is what users attach to bug reports. Log only the key type and length. Co-Authored-By: Claude Opus 5.5 --- .../bluetooth/aacp/packet/MagicKeysResponsePacket.kt | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/android/app/src/main/kotlin/me/kavishdevar/librepods/bluetooth/aacp/packet/MagicKeysResponsePacket.kt b/android/app/src/main/kotlin/me/kavishdevar/librepods/bluetooth/aacp/packet/MagicKeysResponsePacket.kt index 69f1d99aa..f6fafe22b 100644 --- a/android/app/src/main/kotlin/me/kavishdevar/librepods/bluetooth/aacp/packet/MagicKeysResponsePacket.kt +++ b/android/app/src/main/kotlin/me/kavishdevar/librepods/bluetooth/aacp/packet/MagicKeysResponsePacket.kt @@ -43,10 +43,12 @@ data class MagicKeyResponsePacket( try { keys[MagicKeyType.fromByte(keyType)] = key } catch (e: Exception) { - Log.e(TAG, "incorrect key type received: $keyType, ${key.toHexString()}", e) + Log.e(TAG, "incorrect key type received: $keyType", e) } offset += keyLength - Log.d(TAG, "Parsed Proximity Key: Type: ${keyType}, Length: $keyLength, Key: ${key.toHexString()}") + // never log the key itself: the IRK/encryption key let anyone resolve and decrypt these AirPods' BLE + // advertisements, and logs end up in bug reports + Log.d(TAG, "Parsed Proximity Key: Type: ${keyType}, Length: $keyLength") } return MagicKeyResponsePacket(keys, payload)