Harvesting email addresses surreptitiously
arvindn.livejournal.com
arvindn.livejournal.com
A further comment:
Suppose you implement this and lots of people are visiting your page, then you may have a problem determining which visitor corresponds to which email address, since each query to Google docs will return multiple addresses. One way to get around that would be to create 10 documents; for each visitor, embed a random subset of the documents. This way you can uniquely identify visitors as long as you have fewer than 1024 visitors within a minute or two.
"You just convinced me to not stay logged on to Google. Ever!"
So Chrome has a "New Incognito Window" option, what about a "New Anonymous Window" option that would be like incognito but without any of your sessions/cookies/whatever, like a seperate sandbox or something.
They don't even allow cookies within an incognito window.
It seems like a pretty bad oversight on Google's part to allow this.
Because if so, that's the problem right there. It's not a security "design flaw" of some kind -- it's a flat out failure of Google to protect the privacy of its users -- and I have to imagine a violation of its privacy policy.
I don't know, maybe I'm missing something though.
It should be noted that this assumption is usually, but not always, true.
It's possible to create a google account with a non @gmail.com address (I have two myself). I just tested and confirmed that Google Docs shows the local part of the email address but not the domain.
So you couldn't be 100% sure that "john.doe" is john.doe@gmail.com, though it would obviously be a pretty solid guess.
Now looking for a chrome plugin similar to NoScript.
..please don't.
There are plenty of ways for good hackers to be successful while still being open, honest, and forthright with everyone else. Don't be tempted to take a shortcut that someone else might consider dishonest or underhanded. It just ain't worth it.