Crypto flaw reveals pollies' hateful anonymous comments

By
Follow google news

Swedish journalists find weak crypto function.

Swedish journalists were able to match hateful online anonymous comments to politicians through a weakness found in an API services' cryptographic function.


A blogger at Expressen, the Swedish publication that performed the hack along with a separate investigative group of journalists, was able to crack the cryptographic hashes used by Gravatar, a third-party service that allows users to display the same avatar across multiple platforms.

By doing so, they were able to identify the authors of many anonymous comments left on right-wing blogs.

The service is used by the popular web comment-hosting provider Disqus. In a Tuesday blog post, the service announced that it was not “cracked,” but that it would be disabling Gravatar. According to the post, Disqus believes that the journalists' actions violated its privacy guidelines.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Researchers find critical vulnerabilities in cloud-based password managers

Researchers find critical vulnerabilities in cloud-based password managers

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Victoria's whole-of-government CISO has left

Victoria's whole-of-government CISO has left

Woolworths splits infosec and physical security again

Woolworths splits infosec and physical security again

Log In

  |  Forgot your password?