4 ms·
I’ve implemented email blocking recently where we stored a secure hash of the blocked email so we know we’ve seen it, but we don’t have it stored. So it is pos
by craz8 6y ago
I’ve implemented email blocking recently where we stored a secure hash of the blocked email so we know we’ve seen it, but we don’t have it stored. So it is possible to do that correctly
Discord probably doesn’t do that though
- CodesInChaos 6y agoHashing is better than storing it in the clear, but many email addresses have too low entropy to make hashing an effective anonymization.
- lathiat 6y agoSomeone did a pretty good analysis of that problem here: https://medium.com/@matthew.bajorek/using-hashcat-to-recover-hashed-emails-8ba306aab18a https://medium.com/@matthew.bajorek/using-hashcat-to-recover...
- CodesInChaos 6y agoI ran such an attack on stackoverflow's data dump in 2011 and recovered about 28% of emails, using only a simple laptop CPU. https://meta.stackexchange.com/questions/44717/is-gravatar-a-privacy-risk/84734#84734 https://meta.stackexchange.com/questions/44717/is-gravatar-a... Somebody else ran a similar attack on a different dataset using a GPU and recovered around 45%. https://arstechnica.com/information-technology/2013/12/crypto-weakness-in-web-comment-system-exposes-hate-mongering-politicians/ https://arstechnica.com/information-technology/2013/12/crypt...