Tor bridges log their fingerprint during startup

I think that behaviour should be changed to use safelogging here, because when
people share their notice level log, they reveal their bridge's fingerprint otherwise.

Will make a patch if people agree. Nick, Roger?

Sure thing. We should make sure they don't log their own address either. (Not that they do, but I don't think
we ever considered that "one's own address" would be sensitive.

I disagree. People use that log line to figure out their bridge address, so they
can share it with people manually.

If you have Vidalia, it shows you a bridge address in the relay window.

But if you don't have Vidalia, how else are you supposed to learn the bridge address
to tell people?

Can I close as notabug, or do you still think this should change?

Hm. What about the fingerprint file?

What about it?

(Moving this ticket into the "unspecified" milestone. Please move it out if we can figure out a course of action.)

If you mean "what about the fingerprint file, can't they use the value in that to tell people their bridge address", then yes, but having two places they can look increases usability. Before we put it in the log too, some people were having troubles finding their datadir and then finding the file in it.

If you mean "what about the fingerprint file, that has a sensitive string in it too", then we should ask why we're writing the bridge's identity key to disk too.

I meant the former, why not find the fingerprint in the fingerprint file. If this is for usability for bridge operators we should probably log "give this string to your friends who need a bridge: 'ip:port fp'"

