Crypto flaw reveals pollies' hateful anonymous comments

By on

Swedish journalists find weak crypto function.

Swedish journalists were able to match hateful online anonymous comments to politicians through a weakness found in an API services' cryptographic function.

A blogger at Expressen, the Swedish publication that performed the hack along with a separate investigative group of journalists, was able to crack the cryptographic hashes used by Gravatar, a third-party service that allows users to display the same avatar across multiple platforms.

By doing so, they were able to identify the authors of many anonymous comments left on right-wing blogs.

The service is used by the popular web comment-hosting provider Disqus. In a Tuesday blog post, the service announced that it was not “cracked,” but that it would be disabling Gravatar. According to the post, Disqus believes that the journalists' actions violated its privacy guidelines.

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Log In

Username:
Password:
|  Forgot your password?