Gravatars: why publishing your email's hash is not a good idea
developer.it
developer.it
At this point, I think I could spot a piece of spam tip-toeing through the brush at 300 yards.
I used to quickly look through my spam folder in GMail and then flush it whenever it went above a certain amount of messages. Now I don't have that compulsion anymore, since there is an option to not display the unread count.
I just let the spam folder alone. If there is any false positive, and if it is important enough, the sender will most likely send another message and the probability of multiple false positives is lower.
Yes, it's a lot. And yes, as Batsu said, I'm numb to the pain.
Filtering those manually became unworkable for me years ago.
I maybe see a spam in my inbox once a day. It goes up and down, as spammers find workarounds and then Google fix them.
The email address I use is 10+ years old though.
Say, you suspect that Alice on stack overflow bad-mouthing software vendor "HAL", claiming impartiality, is really Eve, working for competing software vendor "Moon", you might be able to confirm that by using your knowledge of moon.com e-mail addresses, and checking the hash of eve@moon.com, causing SO to breach the privacy Alice/Eve expected when signing up.
Technically, yes, this article is correct. The Gravatar FAQ even discusses this issue, IIRC. But in practical usage, I can't imagine how this would prove important.
my.address+really_long_random_string@famousprovider.com
as your Gravatar e-mail. Will work if famousprovider==gmail at least. really_long_random_string
to register for every gravatar-enabled site you want to register for.The only benefit I can see of this is that you could easily blacklist emails destined for that address.
A ton of people validate addresses using Regular Expressions but don't have the fortitude to copy-paste the monster regex needed to do it correctly.
You just have to associate the + address with your account - you can even give it a different image so you could have a different identity on every site without needing multiple email addresses.
- Unomi -
When I first read the article, I thought the same thing. If each site had their own salt key (probably based upon a id), then this problem goes away.
It could get even easier if the domain name captured via the http referrer was used as the salt, then Gravatar.com wouldn't even need a UI to let sites sign up. This might make it a little more difficult for a site operator though, so ideally this would be a configurable option.
If you do use an easily guessable e-mail address, Google has been pretty darn good at finding e-mail addresses for years. I could Google various permutations of a username and famous e-mail providers in far less time than it takes to write a Haskell program. (It'd be even easier if Google indexed the @ token...hmm, I wonder if I should be codesearching for e-mail addresses instead.)
And if all you want is a list of e-mail addresses, you could just run a crawler and a few regexps, and you'll find way more than 8500 in a few hours.
"Who leaked this info?" "I don't know but it's someone who looks just like Bill! They even use the same gravatar image he uses everywhere else! Devious bastards! Let's see if we can reverse engineer this email hash to find out who this rogue might be!"
I'll give a shiny nickel to the first person that can reverse this hash: 9b60573dba6b13029b245bbdf7d01323
Moral: Not everyone uses some variation on their name nor do they use the most common email providers.
My email address is all over the internet. So what.
I know this ofcourse, and will use a different e-mail address if I need to keep these identities seperate, but many people do not realize any gravatar enabled user profile can be linked to any other gravatar enabled user profile with only a tiny bit of effort in harvesting.
(fwiw i currently use gmail for spam filtering, but have also had success with spamassassin)