2 ms·
MD5 hashes of emails is very common practice for Gravatar etc. - although it's fairly sucky, I'm assuming this is in the API specifically for things like showin
by cubehouse 13y ago
MD5 hashes of emails is very common practice for Gravatar etc. - although it's fairly sucky, I'm assuming this is in the API specifically for things like showing Gravatar images.
I reported a username -> plaintext email vuln to Disqus earlier this year and they were very prompt in patching it, I wouldn't criticize them for this at all as this a very common issue across most blog comment systems.
Would be nice to change how Gravatar works, but it's fairly fundamental. I think if you want your email to be private you should probably be registering temporary ones or using the + aliases like gmail offers to avoid these kinds of hash-cracking attacks.
- amckenna 13y agoAnother solution would be for these services to use something with a greater work factor than MD5. When a typical user can brute force MD5s at a rate of 8.5 billion per second with AMD HD7970 graphics card then it's time to use a different hashing algorithm. Something like scrypt or bcrypt with a larger work factor would make these attacks much harder and more expensive, while leaving the fundamentals of the system the same. http://hashcat.net/oclhashcat/ http://hashcat.net/oclhashcat/ https://www.tarsnap.com/scrypt.html https://www.tarsnap.com/scrypt.html https://en.wikipedia.org/wiki/Bcrypt https://en.wikipedia.org/wiki/Bcrypt