Live data from Hacker News

Disqus cracked – Security flaw reveals users’ e-mail addresses

cornucopia-en.cornubot.se

11–20 of 92 posts

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#11

The article is a bit miss leading. The so called security flaw does not reveal the e-mail address directly, but a MD5 hash of it. Sure it can be cracked, but it doesn't mean that it will get cracked.

Actually, yeah, it will be cracked, by someone.

And E-Mail-addresses aren't passwords; trying a few hundred variations for each firstname for each lastname is perfectly feasible and should crack a nice percentage of these hashes.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#12
post #7
post #6

In all our worry about NSA taps, the simple fact is that gravatar and now disqus allows anyone NSA, your health insurance company, groups who dislike your group, etc., to track your blog comments, help desk comments, any comment you make around the net. Your comments to gay rights groups, anti-gay rights groups, cancer support groups, aids support groups, abortion groups, democratic politics, tea party groups, gun ri…

Any comments you make under your email address are attributable to that email address. Duh. The whole point of gravatar and disqus is to make it clear that your comments on a bunch of different sites are from the same person. If you don't want a particular comment associated with your name or email, why would you ever fill in that name or email when commenting?

From the same person, but not from that email address. Bad idea, but as per the article people expect these posts not to be linkable to their e-mail address. Why? Well, obviously, because that's the way Disqus works "usually".

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#14

The article is a bit miss leading. The so called security flaw does not reveal the e-mail address directly, but a MD5 hash of it. Sure it can be cracked, but it doesn't mean that it will get cracked.

Actually, yeah, it will be cracked, by someone . And E-Mail-addresses aren't passwords; trying a few hundred variations for each firstname for each lastname is perfectly feasible and should crack a nice percentage of these hashes.

My email is firstname@companyname.co.nz (I have a few of these at different companies). I'm fairly confident this isn't going to be cracked any time soon by random MD5 hashing.

(of course, my real name can be extrapolated from my HN username)

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#15

Old olllddd news, almost every Wordpress blog uses Gravatar, same issue...

So why do you feel compelled to post when you know what you are saying is old news? You just adds to the noise and make it off putting for anyone else to post that actually knows about this event including your obvious point.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#16
post #7
post #6

In all our worry about NSA taps, the simple fact is that gravatar and now disqus allows anyone NSA, your health insurance company, groups who dislike your group, etc., to track your blog comments, help desk comments, any comment you make around the net. Your comments to gay rights groups, anti-gay rights groups, cancer support groups, aids support groups, abortion groups, democratic politics, tea party groups, gun ri…

Any comments you make under your email address are attributable to that email address. Duh. The whole point of gravatar and disqus is to make it clear that your comments on a bunch of different sites are from the same person. If you don't want a particular comment associated with your name or email, why would you ever fill in that name or email when commenting?

If I go to comment at a wordpress site it says this:

"Email (required) (Address never made public)"

MD5 leaks of my email address into web pages is in fact making my address public.

Hey lmm, duh, when you make a comment under a different name but with the same email address that you think is anonymous at your local hiv testing site, you may not expect that your insurance company can track that down because wordpress has been leaking your md5 address all over the place.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#18
post #14

Earlier quoted context omitted.

Actually, yeah, it will be cracked, by someone . And E-Mail-addresses aren't passwords; trying a few hundred variations for each firstname for each lastname is perfectly feasible and should crack a nice percentage of these hashes.

My email is firstname@companyname.co.nz (I have a few of these at different companies). I'm fairly confident this isn't going to be cracked any time soon by random MD5 hashing. (of course, my real name can be extrapolated from my HN username)

How many *.co.nz's are there? 1,000,000? 10,000? How many first names are there? People can generate millions of MD5's per second now-a-days.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#19
post #14

Earlier quoted context omitted.

Actually, yeah, it will be cracked, by someone . And E-Mail-addresses aren't passwords; trying a few hundred variations for each firstname for each lastname is perfectly feasible and should crack a nice percentage of these hashes.

My email is firstname@companyname.co.nz (I have a few of these at different companies). I'm fairly confident this isn't going to be cracked any time soon by random MD5 hashing. (of course, my real name can be extrapolated from my HN username)

The rainbow table would just need to include alphanumeric letters + '@' for up to 30 letters. I think your emails are in nearly every rainbow table in existence.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#20
post #7

Earlier quoted context omitted.

Any comments you make under your email address are attributable to that email address. Duh. The whole point of gravatar and disqus is to make it clear that your comments on a bunch of different sites are from the same person. If you don't want a particular comment associated with your name or email, why would you ever fill in that name or email when commenting?

If I go to comment at a wordpress site it says this: "Email (required) (Address never made public)" MD5 leaks of my email address into web pages is in fact making my address public. Hey lmm, duh, when you make a comment under a different name but with the same email address that you think is anonymous at your local hiv testing site, you may not expect that your insurance company can track that down because wordpress…

>If I go to comment at a wordpress site it says this: "Email (required) (Address never made public)"

So wordpress - not disqus or gravatar (which I'm aware is owned by wordpress) - is lying to you. Let's put the blame in the right place.

Post reply on HN