Files
OpsLog/wiki/Security.md
T
rouggy 246ecf23ba Revert "feat: remove PostHog usage telemetry entirely"
This reverts commit 6a28344. Restore the once-a-day anonymous PostHog heartbeat
and its opt-out toggle: telemetry.go (sendTelemetryHeartbeat, GetTelemetryEnabled/
SetTelemetryEnabled, PostHog host + API key), the startup goroutine, the Settings
→ General toggle + i18n keys, and the README/wiki mentions. version.go is dropped
again (appVersion moves back into telemetry.go). release.ps1 (untracked) pointed
back at telemetry.go by hand.
2026-07-24 15:24:22 +02:00

919 B

Security

Secret vault

Opt-in passphrase encryption of the stored passwords (QRZ, cluster, eQSL, SMTP, Icom network, etc.) using AES-GCM + PBKDF2.

  • Enable it in Settings; you set a passphrase.
  • Encrypted values are marked enc:v1: and are portable (they travel with the data/ folder).
  • A single unlock prompt at launch decrypts them for the session.

If you forget the passphrase, the encrypted secrets can't be recovered — re-enter them.

What OpsLog sends where

  • Callsign lookups go to QRZ.com / HamQTH with your credentials.
  • QSL uploads/downloads go to the services you configure (LoTW via TQSL, QRZ, eQSL, ClubLog, HRDLog).
  • Telemetry is a once-a-day anonymous heartbeat (random install ID + version
    • OS — no callsign, no QSO data). Opt out in Preferences.
  • Everything else stays local (or on your own MySQL / web server for the multi-op live status).