3 ms·
I guess the point is to not store ip addresses. Given the focus on allowing anonymous commenting [1] this seems to make sense. [1]: http://posativ.org/isso/do
by trurl42 12y ago
I guess the point is to not store ip addresses.
Given the focus on allowing anonymous commenting [1] this seems to make sense.
[1]: http://posativ.org/isso/docs/#what-s-wrong-with-disqus http://posativ.org/isso/docs/#what-s-wrong-with-disqus
- kevan 12y agoIn that case you could store a hash of the IP instead.
- girvo 12y agoWith a known structure, a hashed IP could be reversed quite easily couldn't it?
- infogulch 12y agoWe're limited to ipv4 so even if you hash it you could still test every possible address within a few minutes. You can even do the same with the bloom filter, since there's at worst only a 1/1000 false positive rate (and likely much smaller). The bloom filter isn't designed to provide security, and trying to make (ipv4) IPs private if you're using them as identities is a lost cause.