HomeSecurity

Is TMPlayer safe?

Every line of it is public, every release is built by GitHub from that public source, and you can check the file you downloaded yourself. Here is how.

Your Telegram account

What the app does with your sign-in, and where it talks to.

Telegram's own library

Sign-in and every request go through TDLib, Telegram's official client library, straight to Telegram. You approve the sign-in from your phone, and it shows up in Telegram's list of devices, where you can end it.

The session stays on the device

There is no TMPlayer account and no TMPlayer server. Your session, settings and downloads live in the app's own storage on your TV, phone or computer.

No analytics in the app

No analytics, no advertising library, no tracking. On Android, crash reports go out only if you switch them on in Settings; they are off until then.

Besides Telegram, the app asks tmplayer.org for one small file naming the newest release, and GitHub for an update when you choose to install it. The privacy page lists everything, including what a crash report holds.

How a release is made

In public, by a machine, from the source you can read.

  1. Open source, GPL-3.0

    All of TMPlayer's code is on GitHub under the GPL-3.0. Anyone can read it, build it and compare.

  2. Built by GitHub Actions from the tag

    A release starts as a version tag. GitHub's own servers then check out that tag and build the APK, the MSI, the AppImage and the Linux tarball from it. The recipe is public: release.yml, and each run is listed on the repository's Actions tab.

  3. The APK is signed there, with the project's key

    The signing key is a secret that only the release job can read, and it is deleted from the build machine as soon as the APK is signed. Android will only install an update over TMPlayer if it carries the same signature.

  4. Every file gets a SHA-256

    The release page on GitHub shows the SHA-256 of each file. The same job writes latest.json, the update feed the app reads, with each package's size and SHA-256 taken from the published bytes.

  5. The app checks it before updating

    When you press Update now, TMPlayer downloads the new package and compares its SHA-256 with the one in the feed. If they differ, it deletes the file and says the download was damaged. Nothing is installed until you press the button.

Check the file yourself

Compare the result with the SHA-256 beside the file on the release page, or in latest.json. They should match letter for letter.

Linux or macOS

sha256sum TMPlayer-<version>-x86_64.AppImage

On macOS, shasum -a 256 does the same.

Windows, in PowerShell

Get-FileHash .\TMPlayer-<version>-windows-x64.msi

SHA-256 is its default. The hash is printed in capitals, which does not matter.

Android, the signature too (optional)

apksigner verify --print-certs TMPlayer-<version>-universal.apk

apksigner comes with the Android SDK build tools. The certificate's SHA-256 should be the same from one release to the next.

Any file, where it was built (optional)

gh attestation verify TMPlayer-<version>-windows-x64.msi --repo dracu-lah/TMPlayer

Releases after 1.22.0 carry a build attestation for every file: a statement, signed through GitHub and Sigstore, that the file came out of the release workflow at that version's tag. The GitHub CLI checks it, and the command works the same for the APK, the AppImage and the tarball.

Warnings you may see

What they mean, honestly.

Windows SmartScreen

The Windows installer is not code signed yet. A certificate costs money every year, and until there is one, Windows says Windows protected your PC about any unsigned download it has not seen many times.

It means Windows does not know the publisher, not that it found anything. Check the SHA-256 above, then click More info and Run anyway.

Antivirus and VirusTotal

To get a second opinion, upload the file you downloaded to virustotal.com, which runs it past dozens of scanners at once.

Apps from outside the stores sometimes draw a generic flag from one or two engines. If one names something specific, please tell us.

Android: install from an unknown source

Android asks before installing any app that does not come from a store, and TMPlayer is not in one. That prompt is the same for every sideloaded app. The SHA-256 and the signature check above are how you know this one is the file GitHub built.

Found a security problem?

Please report it privately rather than in a public issue. You will get a reply within a week, and credit once it is fixed if you would like it.

The security policy Only the latest release gets fixes