It is currently Tue Apr 16, 2024 1:46 am

All times are UTC - 8 hours [ DST ]




Post new topic Reply to topic  [ 16 posts ] 
Author Message
Offline
 Post subject: Gravatar for profile picture
Post #1 Posted: Sun Feb 05, 2012 6:38 am 
Lives in gote
User avatar

Posts: 499
Location: Germany
Liked others: 213
Was liked: 96
Rank: Fox 3D
GD Posts: 325
I am trying to upload a profile picture and obviously, I have to register on Gravatar to do this.

Well o.k., if there is no other way ... I provided my email adress for registration and recieved an activation link. Now I have to provide a user name and it tells me that 'SpongeBob' is already taken.

I did not check out the benefits for registering an account on Gravatar, but for me personally, there probably is none. Hope there will be a simple 'Upload profile picture' functionality in the future ...

PS: Happy birthday, Gabriel!

_________________
Stay out of my territory! (W. White, aka Heisenberg)

Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #2 Posted: Sun Feb 05, 2012 7:46 am 
Lives in gote
User avatar

Posts: 643
Location: Munich, Germany
Liked others: 115
Was liked: 102
Rank: KGS 3k
KGS: LiKao / Loki
I just want to note that every website that uses gravatar leaks information about its users' email addresses. This can be used to recover a significant fraction of the email addresses. A quick test revealed 20% of Stackoverflows addresses, but with more effort I believe >50% should be possible.

This leak occurs even if the user isn't registered on gravatar at all. And many websites(stackoverflow, most blogs,...) who do this promise to "never reveal your email address", which IMO is very misleading/borderline lying.

_________________
Sanity is for the weak.


Last edited by Li Kao on Sun Feb 05, 2012 11:34 am, edited 1 time in total.

This post by Li Kao was liked by: topazg
Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #3 Posted: Sun Feb 05, 2012 11:16 am 
Oza
User avatar

Posts: 2508
Liked others: 1304
Was liked: 1128
I've said this before, but I'll say it again, just to see if anyone wants to concur: I don't at all like the idea of having to register with a 3rd party website in order to have a kaya avatar. I don't know much about Gravatar, but I don't particularly like what I've heard, for example that it is not possible to delete your account. I also don't like the idea that whatever picture I choose for kaya will become by default my avatar elsewhere. Not everywhere do I want to appear as a manga for example. I think it's unreasonable to expect that everybody who wants to have a kaya avatar is happy to agree to Gravatar's terms of service. I'm not. Gabriel has said that it's too much work to check every pic by hand, but I don't see why it's even necessary to check them at all. Why not just say in the TOS what's allowed and what isn't?

_________________
Patience, grasshopper.

Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #4 Posted: Sun Feb 05, 2012 11:54 am 
Lives with ko

Posts: 294
Liked others: 25
Was liked: 78
Rank: 6d
KGS: Dexmorgan
Wbaduk: c0nanbatt
daal wrote:
I've said this before, but I'll say it again, just to see if anyone wants to concur: I don't at all like the idea of having to register with a 3rd party website in order to have a kaya avatar. I don't know much about Gravatar, but I don't particularly like what I've heard, for example that it is not possible to delete your account. I also don't like the idea that whatever picture I choose for kaya will become by default my avatar elsewhere. Not everywhere do I want to appear as a manga for example. I think it's unreasonable to expect that everybody who wants to have a kaya avatar is happy to agree to Gravatar's terms of service. I'm not. Gabriel has said that it's too much work to check every pic by hand, but I don't see why it's even necessary to check them at all. Why not just say in the TOS what's allowed and what isn't?


Because the TOS is not working code , and when someone breaks it requires manual labor to react. Saying in the TOS that sexually explicit content is not allowed doesnt not prevent users from putting such pictures. You have to prevent such cases, not fix them when they happen.

I know that many people find it akward to register somewhere else, but its really just that feeling. The only thing that Gravatar does is relate an email address to a picture.


It is extremely comfortable for us at this stage, because they provide storing, cropping (changing the size ) and other details that save us work at this stage and we dont have to check the pictures, and make the system so other volunteeers can do it. So its likely we wont change gravatar in a while, until it becomes a priority.

We do recognize that registering in another website looks quite weird and is uncomfortable, so we will look for another solution. The main issue as i see it, and many developers thing alike, is that they don't provide an api to do it with white labeling.

Li Kao wrote:
I just want to note that every website that uses gravatar leaks information about its users' email addresses. This can be used to recover a significant fraction of the email addresses. A quick test revealed 20% of Stackoverflows addresses, but with more effort I believe >50% should be possible.

This leak occurs even if the user isn't registered on gravatar at all. And many websites(stackoverflow, most blogs,...) who do this promise to "never reveal your email address", which IMO is very misleading/borderline lying.


Source for leaking? it would be pretty awful for StackOverflow if people knew they were selling emails.

If you are talking about the guessing mechanism, its really over-paranoid. To put it into context for people that don't know about that, is that because Gravatar saves a hash (a mathematically irreversible operation on the email address that always returns the same value) that is later used to indentify pictures, you can in principle hash any email and see if Gravatar has the email already.
That is almost the same as sending emails to the addresses you are trying to guess.

StackOverflow had this discussion about it, specially because a lot of people use their names on their account. So say, my name is gabriel Benmergui, and you can try gabrielbenmergui@gmail.com/yahoo/hotmail. That is not a leak in Gravatar.

SpongeBob wrote:
I am trying to upload a profile picture and obviously, I have to register on Gravatar to do this.

Well o.k., if there is no other way ... I provided my email adress for registration and recieved an activation link. Now I have to provide a user name and it tells me that 'SpongeBob' is already taken.

I did not check out the benefits for registering an account on Gravatar, but for me personally, there probably is none. Hope there will be a simple 'Upload profile picture' functionality in the future ...

PS: Happy birthday, Gabriel!


There is probably no visible benefit to you unless you use other sites with Gravatar (like wordpress, stackoverflow, some other blog spaces). The invisible one is that you have pictures today instead of later, because it was a 5 minute work :).

_________________
Founder of Kaya.gs

Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #5 Posted: Sun Feb 05, 2012 1:06 pm 
Lives in gote
User avatar

Posts: 643
Location: Munich, Germany
Liked others: 115
Was liked: 102
Rank: KGS 3k
KGS: LiKao / Loki
Kaya.gs wrote:
Li Kao wrote:
I just want to note that every website that uses gravatar leaks information about its users' email addresses. This can be used to recover a significant fraction of the email addresses. A quick test revealed 20% of Stackoverflows addresses, but with more effort I believe >50% should be possible.

This leak occurs even if the user isn't registered on gravatar at all. And many websites(stackoverflow, most blogs,...) who do this promise to "never reveal your email address", which IMO is very misleading/borderline lying.


Source for leaking? it would be pretty awful for StackOverflow if people knew they were selling emails.


I'm talking about brute force guessing email addresses that match a hash. My attempt with only 10 billion guesses recovered 20% of stackoverflows email addresses. Using better implementations or GPUs much larger hash rates are possible(hashcat claims 10GHash/s on a good graphics card), and my email address generation algorithm was pretty primitive too. So I believe that a larger fraction of addresses can be recovered using this method.

This doesn't cover only email addresses where username=email addresses, but all emails with a reasonably predictable format. Many people use combinations of firstname, lastname, initials and a number. The total entropy of this is in many cases brute-forcible, since gravatar was stupid enough to use a plain md5 hash.

A hash function is only irreversible if the domain is large enough, and I believe that many email addresses have low enough entropy to be recovered.

_________________
Sanity is for the weak.


Last edited by Li Kao on Sun Feb 05, 2012 1:51 pm, edited 5 times in total.
Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #6 Posted: Sun Feb 05, 2012 1:32 pm 
Dies with sente

Posts: 86
Location: Finland
Liked others: 17
Was liked: 12
Rank: KGS 4 kyu
I see having to register to a third party website as counter-intuitive and a questionable course of action. Kaya has given the image of being designed to be easy to use with as little hassle as possible when it comes to starting to use its services etc, and this clearly goes against the idea.

In my opinion, it would be better to not allow avatars at all until it's possible to have them as part of Kaya itself. Don't make people register to other websites, especially if there's some untrustworthiness related to Gravatar, as mentioned in previous comments.

Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #7 Posted: Sun Feb 05, 2012 1:38 pm 
Lives in sente
User avatar

Posts: 1103
Location: Netherlands
Liked others: 408
Was liked: 422
Rank: EGF 4d
GD Posts: 952
Yeah, I agree with walpurgis.

Are unique Avatars a requirement? If you don't want people moderating the avatars, don't have them. But don't ship the service out, that's just a lot of hassle.

_________________
Tactics yes, Tact no...

Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #8 Posted: Sun Feb 05, 2012 1:52 pm 
Lives in gote
User avatar

Posts: 643
Location: Munich, Germany
Liked others: 115
Was liked: 102
Rank: KGS 3k
KGS: LiKao / Loki
I'm not against using gravatars. They are convenient, since they are shared between websites. But I want to promote honesty, where websites using gravatar clearly state that it's often possible to recover email addresses from gravatar's md5 hashes.

IMO the best option is a gravatar opt-in checkbox which explains this issue.

_________________
Sanity is for the weak.

Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #9 Posted: Sun Feb 05, 2012 2:37 pm 
Lives with ko

Posts: 294
Liked others: 25
Was liked: 78
Rank: 6d
KGS: Dexmorgan
Wbaduk: c0nanbatt
Li Kao wrote:
I'm not against using gravatars. They are convenient, since they are shared between websites. But I want to promote honesty, where websites using gravatar clearly state that it's often possible to recover email addresses from gravatar's md5 hashes.

IMO the best option is a gravatar opt-in checkbox which explains this issue.
shapenaji wrote:
Yeah, I agree with walpurgis.

Are unique Avatars a requirement? If you don't want people moderating the avatars, don't have them. But don't ship the service out, that's just a lot of hassle.
walpurgis wrote:
I see having to register to a third party website as counter-intuitive and a questionable course of action. Kaya has given the image of being designed to be easy to use with as little hassle as possible when it comes to starting to use its services etc, and this clearly goes against the idea.

In my opinion, it would be better to not allow avatars at all until it's possible to have them as part of Kaya itself. Don't make people register to other websites, especially if there's some untrustworthiness related to Gravatar, as mentioned in previous comments.


Signing up for gravatar is absolutely optional, we are not forcing anyone.

_________________
Founder of Kaya.gs

Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #10 Posted: Sun Feb 05, 2012 2:43 pm 
Lives in gote
User avatar

Posts: 643
Location: Munich, Germany
Liked others: 115
Was liked: 102
Rank: KGS 3k
KGS: LiKao / Loki
Kaya.gs wrote:
Signing up for gravatar is absolutely optional, we are not forcing anyone.

Do you mean that users can opt-in/out of you displaying the md5 of their email address? Singing up to gravatar itself it unrelated to the privacy issues.

_________________
Sanity is for the weak.

Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #11 Posted: Sun Feb 05, 2012 3:16 pm 
Lives in gote
User avatar

Posts: 499
Location: Germany
Liked others: 213
Was liked: 96
Rank: Fox 3D
GD Posts: 325
Good to hear that Gravatar is not meant to be the final solution. (I was assuming there was some kind of philosophy behind using it.)

_________________
Stay out of my territory! (W. White, aka Heisenberg)

Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #12 Posted: Sun Feb 05, 2012 3:55 pm 
Lives with ko

Posts: 294
Liked others: 25
Was liked: 78
Rank: 6d
KGS: Dexmorgan
Wbaduk: c0nanbatt
Li Kao wrote:
Kaya.gs wrote:
Signing up for gravatar is absolutely optional, we are not forcing anyone.

Do you mean that users can opt-in/out of you displaying the md5 of their email address? Singing up to gravatar itself it unrelated to the privacy issues.


You can choose to have an avatar with Gravatar, or get the default. The md5 is still shown because im trying to get the latest image for each account. To go around that, i would have to store the result of fetching an image from gravatar and it's not worth the hassle.

LI KAO's concerns are pretty tech-savyy. Its hard to make the matter sound simple and easy. Here is a discussion in SO http://meta.stackoverflow.com/questions ... urity-risk which has things on both sides.



Regards.

_________________
Founder of Kaya.gs

Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #13 Posted: Sun Feb 05, 2012 8:59 pm 
Lives with ko

Posts: 289
Liked others: 7
Was liked: 42
Rank: 100
GD Posts: 100
Thanks for bringing this up, I won't use a website where my email is leaked in this fashion.

Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #14 Posted: Sun Feb 05, 2012 9:02 pm 
Lives in sente

Posts: 800
Liked others: 141
Was liked: 123
Rank: AGA 2kyu
Universal go server handle: speedchase
Li Kao wrote:

I'm talking about brute force guessing email addresses that match a hash. My attempt with only 10 billion guesses recovered 20% of stackoverflows email addresses. Using better implementations or GPUs much larger hash rates are possible(hashcat claims 10GHash/s on a good graphics card), and my email address generation algorithm was pretty primitive too. So I believe that a larger fraction of addresses can be recovered using this method.


I have to break it to you, but all websites that use email addresses for a username, have to tell you if the address has been used before. this doesn't strike me as that scary.

Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #15 Posted: Mon Feb 06, 2012 3:18 am 
Lives in gote

Posts: 589
Liked others: 0
Was liked: 114
Rank: 2 dan
speedchase wrote:
I have to break it to you, but all websites that use email addresses for a username, have to tell you if the address has been used before. this doesn't strike me as that scary.


I think the worry here is that it allows email addresses to be associated with particular accounts on multiple websites.

It's presumably also different to the general case if the hashed url structure (as I understand it, I haven't really been following in detail) allows rapid checking of significant numbers of addresses. Normally, unless there is an account creation API, checking for existing email addresses is much more laborious.

Top
 Profile  
 
Offline
 Post subject: Re: Gravatar for profile picture
Post #16 Posted: Mon Feb 06, 2012 3:15 pm 
Lives with ko

Posts: 294
Liked others: 25
Was liked: 78
Rank: 6d
KGS: Dexmorgan
Wbaduk: c0nanbatt
amnal wrote:
speedchase wrote:
I have to break it to you, but all websites that use email addresses for a username, have to tell you if the address has been used before. this doesn't strike me as that scary.


I think the worry here is that it allows email addresses to be associated with particular accounts on multiple websites.

It's presumably also different to the general case if the hashed url structure (as I understand it, I haven't really been following in detail) allows rapid checking of significant numbers of addresses. Normally, unless there is an account creation API, checking for existing email addresses is much more laborious.


Thats the feature, not the worry. Right now, for example, im making a tournament organizer for OpenKaya. So people could use that site separately and by using the same email, tournament fixtures can show a user profile picture, making it easier to recognize a player you know on a server, or style it.

_________________
Founder of Kaya.gs

Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 16 posts ] 

All times are UTC - 8 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group