3 ms·
Gravatar should stop their support for unsalted MD5 hashes. It's just too insecure when most people don't understand the implications of sharing a MD5 hash of a
by eadz 11y ago
Gravatar should stop their support for unsalted MD5 hashes. It's just too insecure when most people don't understand the implications of sharing a MD5 hash of a user's email.
- koolba 11y agoThe only way something like Gravatar works is by having something that's directly computable from the source email address (or whatever the identifying field is). Whether it's a MD5, SHA256, or whatever is irrelevant. Similarly having it be a salted (instead of the currently unsalted) hash wouldn't help anything. The salt would need to be public for separate web sites to reference the same avatar for the same email address. Short of authenticated requests to Gravatar (which again kills the point of how it all works), one alternative would be to make the computation function more expensive, either by performing multiple rounds of the hash function or switching to a "slow" hash function (ex: bcrypt or scrypt). The latter would require a fixed salt and wouldn't really work for the use case as it'd slow down any webpage that links to multiple gravatars to a crawl. The real issue here is that the email address space is fairly predictable. If you want HASH($EMAIL) to be unpredictable then instead of first.last@example.com switch to ~ [a-z0-9]{16}\@example\.com.
- ikeboy 11y agoThey need to provide avatar, given hash, i.e. implement a public getavatar(emailhash) function. They don't need to provide hash given account, i.e. getemailhash(comment). If someone uses a unique avatar they can be identified by bruteforcing emails, generating md5s, then querying gravatar, but I assume most users don't change from the default. You also couldn't prove it, because you may have missed a different email which has the same avatar.