top | item 7316719

Ask HN: How much does Gravatar enable NSA/GCHQ profile analysis? Is it fixable?

1 points| __pThrow | 12 years ago

Most Wordpress sites (and many other sites too) add gravatar images derived from the MD5 hash of the email addresses of authors and commenters.

These MD5 hashes can be found in the source html of the page and can be used to track people around the net. With a list of email addresses and their MD5 hashes, anything most people write on multiple separate websites can be found and put back together by the NSA or GCHQ.

In light of widespread internet taps of the sort that made GCHQ's Optic Nerve possible, is it now time to recommend to wordpress authors they turn off the gravatars at their sites?

Can gravatar be fixed to allow users to enjoy these avatars while not making it trivial for the NSA or any other web crawling service to identify and track the users?

discuss

order

No comments yet.