I thought you guys might want to know this:
Gravatars Can Leak Users’ Email Addresses

The gravatar system works by sending an md5 hash of your email address. You can get this from the gravatar url image. Then you can do some guess-n-checks of different emails against the hash. It should be pretty easy to write a script to check most of the major providers. I would assume spammers would be all over this if they aren’t already.

If you are worried about it, you can go to the gravatar site and add another email..one that you don’t mind getting spammed and switch that to your primary. So, probably not a big deal but it’s I think it’s pretty interesting.

Posted by POI on December 16, 2009 at 8:45 am
Posted under: General & News
Tags:

  1. MadaracsNo Gravatar Said,

    I use a gmail account. So it’s all good. :-) Wonder if they’ll fix that or if it isn’t considered a problem…

Add A Comment

You must be logged in to post a comment.