If glassdoor cares so much about anonymity, why didn't they engineer their site in such a way that prevents them from being able to deanonymize reviewers? For instance, not keeping identifying user details after they have been verified?
If glassdoor cares so much about anonymity, why didn't they engineer their site in such a way that prevents them from being able to deanonymize reviewers? For instance, not keeping identifying user details after they have been verified?
I imagine there's some sort of zero-knowledge magic cryptographic thing you can do (or maybe something simpler, like a... Bloom filter?), but perhaps Glassdoor didn't want to go for the effort and expense to implement it.
Just goes to show you, unless you can prove anonymity client-side, never assume you're anonymous on the internet, anywhere.
But even if you want one account to not write multiple reviews, you can flag that an account wrote a review for a company without tying it to -what- review.
You can even disassociate that; hash usernames with the company and store that to track who has written a review. Then, you can only confirm that a given user account has written a review for a company, but not which review is theirs, and given a company you can't determine what users wrote those reviews without attempting to hash every username against it.
And that's if you -absolutely- have to try and prevent an account writing more than one review (again, noting that you can just create another account).
Given even a few million users, this is trivial. Other than that, I agree with you.
The fact that it's impossible to comply with "who wrote -this- review" is probably sufficient, but "and we don't even readily have access to who wrote -a- review" can help prevent fishing expeditions, since presumably a judge will be less amenable to such fishing expeditions if you can show it will have negative material effect to comply, while still not providing any legal path forward to sue for the prosecution.
But that also makes assumptions both of user counts, and rounds of hashing. 50 million users (seems reasonable with Glassdoor), with a sufficiently slow hash that takes a second to compute (easily done) means you'll have to wait a year and a half for results for a given company, or start to parallelize things, and, oh, look, now you have dev time and CPU resources and, well, this has a materially adverse effect on our business, and we'll be left with usernames we still can't release since this discovery order only is valid for this -one- review, and we have no way of knowing which it is.
Just FYI, Glassdoor does NOT try to prove that reviewers are current or former employees. Anybody can post claiming to be an employee, and Glassdoor will accept their review.
It doesn't seem hard to me.
1. when making a review, send a verification link to the email on file
2. after the email is verified, post the review, but delink the email from the actual review.
3. to prevent the same email from being used to spam reviews, add a coarse grained timestamp (eg. rounded to the nearest month, depending on how much activity the company gets) of when it was last used.
4. if you want users to be able to update reviews afterwards, display a secret key to them and keep a hashed version on file. The user must present the secret key if he wants to update his review