4 ms·
The udids have already all been hashed. It is the hashed values only that are stored on the site. The only piece of information sent to the site is a hashed udi
by afitnerd 14y ago
The udids have already all been hashed. It is the hashed values only that are stored on the site. The only piece of information sent to the site is a hashed udid (the udid is hashed on the browser before any information is sent over the wire).
- dfc 14y agoI realize that. But all the site owner has to do is keep a list of the UDID->hash mapping and then he can lookup the original UDID...
- afitnerd 14y agoI think you may be missing the point. I already have all of the 1,000,001 original UDIDs posted by AntiSec. I don't need to go through all that hassle you describe. I wrote the script that generated the hashes from the original UDIDs. The point is that in order to stop people from passing their UDIDs around the net they way some other checking services have made them do, this service does not have any of the original UDID's on local storage. Even if my site is compromised, it will not further the spread of UDID information. Of course, you do have to trust that what I am saying is the truth. Anyone can choose NOT to submit their (hashed) UDID to my site.
- dfc 14y agoI may be missing the point. I am not trying to be difficult, I promise. What is the difference between me sending you my UDID and me sending you my hashed UDID?
- afitnerd 14y agoThe difference is that if my site is compromised or if someone is listening in on the network traffic, no one will be able to take the database of hashed UDIDs and get the original UDIDs.
- afitnerd 14y agoThe difference is that if my site is compromised or if someone is listening in on the network traffic, no one will be able to take the database of hashed UDIDs and get the original UDIDs.
- dfc 14y agoThe original UDIDs are already published. The cat is out of the bag. From what I can see the only difference is that you don't know the submitters UDID if they were not on the published list. FYI: you can get around the no reply box "feature" by clicking "link."
- afitnerd 14y agoprecisely. The cat is already out of the bag. But, my site will not be a vector of "infection" in spreading the existing information or any new information.