I agree that the second notification is a little bit annoying, but in the case of Voxer you DID have a chance to cancel out -- it didn't secretly do it in the background, which Path apparently did.
I agree that the second notification is a little bit annoying, but in the case of Voxer you DID have a chance to cancel out -- it didn't secretly do it in the background, which Path apparently did.
http://blog.textie.me/post/17261989750/keeping-your-address-...
1. In particular, the domain of email addresses is less vulnerable to rainbow tables than the domain of phone numbers.
2. Using salts and a slow hash function improves security by requiring custom rainbow tables that take longer to build.
3. In a B2C situation, an easy appeal to justice can be made that a business should not be making a concerted effort to break its own customer privacy protection. This would not look good in court.
4. If additional consumer protection laws are needed, one-way hashing for the purpose of privacy could be considered a form of pro-consumer DRM. In that realm we have precedents for anti-circumvention laws and contracts.
If their servers are compromised, a cracker could still get MOST of the info. Since the hashing function (and salting mechanism) lives on the phone, she could generate a rainbow table of all possible phone numbers and a set of emails for common domains.
edit: http://www.schneier.com/blog/archives/2009/07/homomorphic_en...