TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Got an account on a site like Github? Hackers may know your e-mail address

38 pointsby marteyalmost 12 years ago

7 comments

Smerityalmost 12 years ago
Singling out GitHub seems silly. If you&#x27;re on GitHub, have a .gitconfig with name + email, and you&#x27;ve made a commit, then that&#x27;s all public.<p>If a site uses your Gravatar, game over: Gravatar&#x27;s literally a raw MD5 of your email with the aim to give you a globally identifiable avatar. That&#x27;s been known (documented!) for a long time and unlikely to be a surprise to many of us here.<p>The only place this is likely to be an issue is when a site knows you but you assume you&#x27;re anonymous. If you&#x27;re using a web service where you want to be anonymous, connecting anything with your identity is a bad idea.
评论 #6138768 未加载
评论 #6138672 未加载
walesmdalmost 12 years ago
Isn&#x27;t this public knowledge? &quot;Oh no! &#x27;Hackers&#x27; have my oh-so-sacred email address! Yeah, that thing on all of my sites, business cards, dozens of whois records, resumes, speaker decks, the Dominoes online ordering system, and so on... What shall I ever do?&quot;<p>I&#x27;d seriously question their talent if they weren&#x27;t able to find it.
评论 #6139210 未加载
cbhlalmost 12 years ago
The article title is link bait. The article is about Gravatar, and GitHub only matters because it utilizes Gravatar.<p>(Your email address may be visible in all sorts of other ways on GitHub, such as when someone does git log on a public git repository.)<p>If you&#x27;re worried about your Gravatar being matched to your inflammatory (i.e., trolling) Hacker News or WordPress comments, you probably should be using a separate email account and Tor and whatnot.
jffalmost 12 years ago
My email address? Oh god no!
评论 #6139011 未加载
评论 #6138670 未加载
评论 #6138965 未加载
thejoshalmost 12 years ago
Doesn&#x27;t github also store it in a json response?
评论 #6138954 未加载
zalewalmost 12 years ago
the gravatar email recovery hack has been known for years, they are recycling an old topic.<p>luckily my email isn&#x27;t a secret as I publish it everywhere willingly.
评论 #6138636 未加载
deadslowalmost 12 years ago
Post something new.