.well-known/avatar
shkspr.mobi
shkspr.mobi
Couldn't it be done with WebFinger though?
{
"links" : [
{
"rel" : "http://webfinger.shkspr.mobi/rel/avatar",
"href" : "https://cdn.ojford.com/images/avatar.png"
}
],
// ...
}But, yes, this might be useful in enumeration attacks - but so is something like WebFinger.
Good points to consider. Thanks!
But, take for example your Keybase URl https://keybase.io/kej - why can't all the services that you've linked to from it pull in your avatar from there as well as your public key?
"Faff around" meaning, like, probably four or so clicks?
It's the same argument for social sign in. Most people can't be bothered with the faff of typing in an email address and password, then clicking on their email to verify, then adding their name.
So they click "Sign in with Facebook / Twitter / GitHub".
https://pypi.org/project/email-normalize/
https://stackoverflow.com/questions/9807909/are-email-addres...
> https://example.org/.well-known/openpgpkey/hu/XXXX
> SHA-1 hashed and z-Base-32 encoded [to distinguish it from a fingerprint]
> The local part is always lower-cased before the encoding. [...] A common example for case-insensitivity are visiting cards which capitalize the canonical lowercase mail address for easier reading.
https://wiki.gnupg.org/EasyGpg2016/PubkeyDistributionConcept
Instead of a query parameter, which always requires a script to process:
example.com/.well-known/avatar?resource=acct:username@example.com
Make the requested email address part of the path:
example.com/.well-known/avatar/username@example.com
People can put images into their HTTP server directory named as email addresses. This makes it easier to implement for vanity domains. No server-side code necessary. It still allows someone to build a dynamic script that handles the "/.well-known/avatar/" path.
While I don't know enough about the nuances to weigh in on this specific proposal, decentralized solutions are going to become increasingly important!
Gravatar was interesting to proof of concept the idea, but it should not be a centralized service, it should be a protocol or protocol extension. Conversely, I am unsure if a directory service specifically for this is needed (versus leaning on existing open and established systems), but I could be wrong.
lol. who needs privacy or the ability to have disconnected identities online? right?
terrible idea.
Just like you advertise your website on your GitHub and your HN profile, I want to make it easy to show my photo on sites that I choose to use. What's wrong with that?
services shouldn't leak user email addresses or that those users use that service.
users shouldn't have to juggle different email addresses to maintain distinct identities on different services.
with gravitar, the user is opting into losing pseudonymity, seeing as it's pretty trivial to take lists of email addresses you want to hunt down, md5 them, and then check them against places that user gravitar comments to identify comments are made by someone specific )
with this suggestion, every user on every email server that supports it, which would likely include all the common large ones if the author had their way, would fall afoul of constant identity leakage across every service they use.
an adversary need only crawl different services and hash the user avatars, spam email servers with requests for addresses dropped in leaks or otherwise available publicly, and match them up to remove privacy from the internet
If you own a domain and your disconnected identities are all tied to the same domain (or email address) then you have exactly the same issue.
you could use this to query the email server, and to crawl various services to match up identities across them.
most users do not own their own domains, and this would have to be implemented on the major free email providers to be useful, offering up every user on them for casual identification via any service that displays their image