Got an account on a site like Github? Hackers may know your e-mail address
arstechnica.com
arstechnica.com
If a site uses your Gravatar, game over: Gravatar's literally a raw MD5 of your email with the aim to give you a globally identifiable avatar. That's been known (documented!) for a long time and unlikely to be a surprise to many of us here.
The only place this is likely to be an issue is when a site knows you but you assume you're anonymous. If you're using a web service where you want to be anonymous, connecting anything with your identity is a bad idea.
While I wish the article headline mentioned Gravatar as opposed to Github, I think it is worth realizing that Github provides instructions to use a fake email address in your .gitconfig to protect your privacy [1] while simultaneously requiring you to provide a valid email address while setting up your account. [2]
[1]: https://help.github.com/articles/keeping-your-email-address-...
[2]: https://help.github.com/articles/github-terms-of-service#a-a...
I'd seriously question their talent if they weren't able to find it.
But Gravatar and sites using Gravatar are terrible at explaining these risks to less technical users. Those users have an expectation of privacy when a site claims they won't share their e-mail address with anyone. No one has told them how incredibly easy it is to verify that their user account on one of the sites they use is the same person as a user account on a different site.
(Your email address may be visible in all sorts of other ways on GitHub, such as when someone does git log on a public git repository.)
If you're worried about your Gravatar being matched to your inflammatory (i.e., trolling) Hacker News or WordPress comments, you probably should be using a separate email account and Tor and whatnot.
I'd like to get an email address that nobody knows. That way when I don't get any email, I won't be disappointed...
slawmaster at... that google email provider.
I managed to decode that after a few hours of brute forcing. You should apply some stronger obfuscation methods.luckily my email isn't a secret as I publish it everywhere willingly.
* A hacker has a leaked database
* Your email and password are in this database
* Your public email is the same one used in the database
* Plain-text passwords are easy to extract from this leaked databases
* You use the same password and email combination other places
* Other places with that email/password don't use two-step authentication
Then if they have your email they can get your password and try it other places
This is the problem. Every password for every account you create should be unique. Bonus points if you use a unique email alias for every account you create too.