Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Security Social Networks

Gravatars Can Leak Users' Email Addresses 170

abell writes "Gravatar offers a global avatar service, using an MD5 hash of the user's email as avatar ID. This piece of information in some cases is enough to retrieve the original email address. Testing a simple attack on stackoverflow.com, I was able to determine the email addresses of more than 10% of the site's users."
This discussion has been archived. No new comments can be posted.

Gravatars Can Leak Users' Email Addresses

Comments Filter:

It is easier to write an incorrect program than understand a correct one.

Working...