Permalink
Browse files

download map preview via https

  • Loading branch information...
DrKLO
DrKLO committed Dec 24, 2013
1 parent d2a6fa4 commit 4f9384afee0cf8e3e6c981f3242534f8d3e932e8
Showing with 1 addition and 1 deletion.
  1. +1 −1 TMessagesProj/src/main/java/org/telegram/ui/ChatActivity.java
@@ -3075,7 +3075,7 @@ public void update() {
} else if (type == 4 || type == 5) {
double lat = message.messageOwner.media.geo.lat;
double lon = message.messageOwner.media.geo._long;
String url = String.format(Locale.US, "http://maps.googleapis.com/maps/api/staticmap?center=%f,%f&zoom=13&size=100x100&maptype=roadmap&scale=%d&markers=color:red|size:big|%f,%f&sensor=false", lat, lon, Math.min(2, (int)Math.ceil(displayDensity)), lat, lon);
String url = String.format(Locale.US, "https://maps.googleapis.com/maps/api/staticmap?center=%f,%f&zoom=13&size=100x100&maptype=roadmap&scale=%d&markers=color:red|size:big|%f,%f&sensor=false", lat, lon, Math.min(2, (int)Math.ceil(displayDensity)), lat, lon);
photoImage.setImage(url, null, message.messageOwner.out ? R.drawable.photo_placeholder_out : R.drawable.photo_placeholder_in);
} else if (type == 11 || type == 10) {
int width = (int)(displaySize.x - (30 * displayDensity));

13 comments on commit 4f9384a

@3mph4515

This comment has been minimized.

Show comment
Hide comment
@3mph4515

3mph4515 Dec 25, 2013

major fix :D

3mph4515 replied Dec 25, 2013

major fix :D

@ysokolovsky

This comment has been minimized.

Show comment
Hide comment
@ysokolovsky

ysokolovsky Dec 25, 2013

so, what's the price of this bug? ;)

ysokolovsky replied Dec 25, 2013

so, what's the price of this bug? ;)

@DrKLO

This comment has been minimized.

Show comment
Hide comment
@DrKLO

DrKLO Dec 26, 2013

Owner

who said that it's a bug?

Owner

DrKLO replied Dec 26, 2013

who said that it's a bug?

@shums

This comment has been minimized.

Show comment
Hide comment
@shums

shums Dec 26, 2013

Geo-location data from user to user was unencrypted and could be stolen

shums replied Dec 26, 2013

Geo-location data from user to user was unencrypted and could be stolen

@DrKLO

This comment has been minimized.

Show comment
Hide comment
@DrKLO

DrKLO Dec 26, 2013

Owner

So what? All geo-location data from mtproto server to client is encrypted, it's just map preview around some geo location. There is no information in which app it was opened or something else. This could be you browser or other app. This is not bug at all. Discussion closed.

Owner

DrKLO replied Dec 26, 2013

So what? All geo-location data from mtproto server to client is encrypted, it's just map preview around some geo location. There is no information in which app it was opened or something else. This could be you browser or other app. This is not bug at all. Discussion closed.

@naryl

This comment has been minimized.

Show comment
Hide comment
@naryl

naryl Dec 26, 2013

I wonder how many more backdoors does Telegram have disguised as "bugs" or even "not bugs".
Or, if it really was a "not bug", you clearly have no idea about how privacy can be compromised and therefore can't be trusted with protecting it.

naryl replied Dec 26, 2013

I wonder how many more backdoors does Telegram have disguised as "bugs" or even "not bugs".
Or, if it really was a "not bug", you clearly have no idea about how privacy can be compromised and therefore can't be trusted with protecting it.

@OShine

This comment has been minimized.

Show comment
Hide comment
@OShine

OShine Dec 26, 2013

The human factor in this case is not good.

OShine replied Dec 26, 2013

The human factor in this case is not good.

@bdbch

This comment has been minimized.

Show comment
Hide comment
@bdbch

bdbch Jan 30, 2014

Dudes, as he said, the location is encrypted with mtproto,
its just the connection to the maps servers which wasn't protected. You could also visit maps and share location without https and it would have the same effect.

bdbch replied Jan 30, 2014

Dudes, as he said, the location is encrypted with mtproto,
its just the connection to the maps servers which wasn't protected. You could also visit maps and share location without https and it would have the same effect.

@bdbch

This comment has been minimized.

Show comment
Hide comment
@bdbch

bdbch Jan 30, 2014

bytheway nice security fix. :)
it was only one s! :D 👍

bdbch replied Jan 30, 2014

bytheway nice security fix. :)
it was only one s! :D 👍

@ZongerX

This comment has been minimized.

Show comment
Hide comment
@ZongerX

ZongerX May 22, 2014

Hardest fix ever :D

ZongerX replied May 22, 2014

Hardest fix ever :D

@soloveiko

This comment has been minimized.

Show comment
Hide comment
@soloveiko

soloveiko Aug 11, 2015

motherOfGod.. what a fix!

soloveiko replied Aug 11, 2015

motherOfGod.. what a fix!

@positively

This comment has been minimized.

Show comment
Hide comment
@positively

positively Sep 20, 2016

What a price for this major fix?) Who knows?)

positively replied Sep 20, 2016

What a price for this major fix?) Who knows?)

Please sign in to comment.