I thought you guys might want to know this:
Gravatars Can Leak Users’ Email Addresses
The gravatar system works by sending an md5 hash of your email address. You can get this from the gravatar url image. Then you can do some guess-n-checks of different emails against the hash. It should be pretty easy to write a script to check most of the major providers. I would assume spammers would be all over this if they aren’t already.
If you are worried about it, you can go to the gravatar site and add another email..one that you don’t mind getting spammed and switch that to your primary. So, probably not a big deal but it’s I think it’s pretty interesting.


I use a gmail account. So it’s all good.
Wonder if they’ll fix that or if it isn’t considered a problem…
Add A Comment
You must be logged in to post a comment.