3 ms·
Yep. The salt would have to public, which would defeat the purpose. However, a user can protect herself by "salting" her own email with an address tag. For exa
by teaspoon 16y ago
Yep. The salt would have to public, which would defeat the purpose.
However, a user can protect herself by "salting" her own email with an address tag. For example, provide tom+ES85jFxz@rpi.edu as your address instead of tom@rpi.edu.
- davidcuddeback 16y agoA few years ago, I tried using email tags with many online services so that I could use the tags for email filters. Most form validations rejected my email tags because they considered "+" to be an invalid character in email addresses.
- spindritf 16y agoUsing your own domain with different local names lets you get around that. But requires a domain.
- dotBen 16y agoI've been using this technique for 10+ years. Sadly it doesn't work with Gravatar because md5("comment+sitename1@mydomain.com") != md5("comment+sitename2@mydomain.com") However, it is really interesting to see the amount of spam I get sent to certain 'snowflake' email addresses I have only ever used to submit a comment to top well known blogs. Shows how much database hacking for email harvest goes on.
- tomjen3 16y agoI ended up using that very same technique and ran into the exact same problem. My solution to this has been to sign up for one gravatar, but after that I simply stopped caring about the service. If whatever service I am using can't work without gravatar, they will have to see a generic picture.
- steveklabnik 16y agoNo, it doesn't. The forms rejected the email as a valid one, probably because they just use a regex like /w+@w+\.\w\w\w/, because they're dumb. It does fix a stupid provider who refuses to accept such an email, though. HTML5 'email' fields should hopefully mean this'll be fixed in approximately 30 years.