4 ms·
It's a good idea to protect user privacy. One drawback I can think of storing a hashed email is - What if the user forgets the username / email id and wants to
by webmobdev 6y ago
It's a good idea to protect user privacy. One drawback I can think of storing a hashed email is - What if the user forgets the username / email id and wants to know it? (This is a common use case). In such a case you have to collect additional unique data to help the user gain access to their account, but that defeats the original purpose - to protect user privacy.
- hardwaresofton 6y agoYou could use a combination of TOTP/google/facebook or some other side channel verification and use that to allow unlimited tries for a certain period of time to allow for more guesses? I'm thinking that for the most part people generally have/keep <5 email addresses (that they use often enough to log in with) so they should be able to just iterate through the list of emails that they've used over their lifetime and figure it out? I do wonder though -- if the hash secret gets out then I think we're right back to where we started... it would be easy to cross-reference leaded email DBs with the dumped DB and work backwards. I'm now a bit less sure this does much for use privacy against an even slightly motivated opponent (one who would almost certainly have access to at least one dump of previously-exposed emails)...
- opk 6y agoPeople often forget usernames but not so often e-mails. The e-mail is usually the primary/only means of identifying users anyway so you're not going to provide it back on request anyway.
- Hitton 6y agoThey won't forget the email, but they might easily forget with which email they registered (happened to me).
- trengorilla 6y agoHow many e-mails could you possibly have that makes trial and error not a good solution in this scenario?
- kd913 6y agoI tend to use aliases so I can filter/discover which exact service is perhaps selling my email. ie <email prefix>+<tag>@gmail.com That tag could be anything or everything.
- danaris 6y agoWell, first of all, I have 5 email accounts that I regularly use. One of those uses multiple domains (it's an iCloud account that I registered way back in the iTools days, so it supports @mac.com, @me.com, and @icloud.com....possibly even @itools.com, not sure about that one). I regularly use a + extension to the addresses that support it when I'm signing up somewhere that I don't 100% trust, and that allows arbitrary additions to the address. And I don't always remember what version of a site's name I will have used (eg, user+hn@example.com, user+hackernews@example.com, user+ycombinator@example.com, etc). I recognize that I'm an outlier, but trial and error is completely infeasible in this scenario.