4 ms·
thats funny... i still have an email from probably 2006 telling gravatar that a single md5 for each user (email address) is just idiotic for many reasons. possi
by to 16y ago
thats funny... i still have an email from probably 2006 telling gravatar that a single md5 for each user (email address) is just idiotic for many reasons. possible collisions, anonymity, and so on.
they replied back within an hour that im wrong, that there is no risk of collision because every email is unique because its the primary key (dah?) and they will continue using it.
made me laugh. since then i ignored the service as they are obvious just a bunch of script kiddies.
to be honest - the only obsticle for such a service is server redundancy. nothing special about it. besides that its now a obsolete service since every major site offers oauth.
- studer 16y agoGiven your statement on MD5 collisions, it's not entirely clear to me who's the script kiddie here.
- to 16y agohow many users do they want to store in their db with a unique md5 string? its just a really bad bet. thats a script kiddie for me, assuming that a hash never collides within a database and than chosing md5. there are better, even very simple, ways to store hashes without forcing collisions.
- ErrantX 16y agoThere are an awful lot of md5 digests - so, even with an insane number of users it is highly unlikely they would have a collision. Hell; at work we generate insane numbers of hashes and it took us quite a while, and a large dataset to find a collision :-)
- gfodor 16y agoNevermind the fact that if the gods did cause such a collision to occur it wouldn't exactly be the end of the world. (And the accessibility of md5 more than makes up for this consequence.)
- to 16y agobut why md5 when there are better alternatives? not to speak about the issues with OP
- philfreo 16y agobecause it's very simple for anyone to build an app that uses Gravatar since md5 is probably the most well-known hashing function.
- wladimir 16y agoAgreed -- It was also my first thought when I read about the service. It's easy to make a database of md5 hashes and link the comments to that, no reason to even decode them. There goes anonymity. This article is only new in that it is (afaik) the first person that actually bothers to test it out and publicize about it.