Live data from Hacker News

Disqus cracked – Security flaw reveals users’ e-mail addresses

cornucopia-en.cornubot.se

1–10 of 92 posts

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#3
The fact that md5 hashes of email addresses can be brute forced is nothing new. This has been pointed out for years, concerning services like gravatar. The only thing which is important, is that Expressen/Researchgruppen believes that they have the right to exploit Disqus' service in order to "make the news".

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#4
Anything requiring third-party cookies, AND requesting an e-mail address not only stinks of spam-oriented advertising revenue, but also total disregard for user security. Even more telling were the options to sign in with services like Facebook Oauth.

So from the beginning, I think it was always obvious that Disqus had no interest beyond the bare minimum in casually protecting user privacy. This prompted me to avoid ever providing Disqus with any kind of serious e-mail address. Looks like my instincts served me well.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#6
In all our worry about NSA taps, the simple fact is that gravatar and now disqus allows anyone NSA, your health insurance company, groups who dislike your group, etc., to track your blog comments, help desk comments, any comment you make around the net.

Your comments to gay rights groups, anti-gay rights groups, cancer support groups, aids support groups, abortion groups, democratic politics, tea party groups, gun rights groups, doctors offices, anyone using wordpress as a front end group.

Anyone can do this with a simple search engine they create, and apparently we don't care because gravatar was setup by a silicon valley favorite and is now owned by Wordpress who was informed of this years ago and refused to consider it a privacy leak. And anyway we like them cutsie cartoon avatars.

Anyone can do this with a search engine that maps pages to md5 hashes and vice versa and either a rainbow table of email addresses, or even easier, a list of your customer's email addresses, because let's see if any of our customers have health problems they didn't disclose.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#7
post #6

In all our worry about NSA taps, the simple fact is that gravatar and now disqus allows anyone NSA, your health insurance company, groups who dislike your group, etc., to track your blog comments, help desk comments, any comment you make around the net. Your comments to gay rights groups, anti-gay rights groups, cancer support groups, aids support groups, abortion groups, democratic politics, tea party groups, gun ri…

Any comments you make under your email address are attributable to that email address. Duh. The whole point of gravatar and disqus is to make it clear that your comments on a bunch of different sites are from the same person.

If you don't want a particular comment associated with your name or email, why would you ever fill in that name or email when commenting?

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#10

The fact that md5 hashes of email addresses can be brute forced is nothing new. This has been pointed out for years, concerning services like gravatar. The only thing which is important, is that Expressen/Researchgruppen believes that they have the right to exploit Disqus' service in order to "make the news".

Why don't/shouldn't they?!

Theres a security problem with Disqus.

Apparently it (genereal technique) is "old news"

Apparently Disqus doesn't care enough to fix it.

Demonstrating the attack may be the only way to get them to care.

Post reply on HN