In the past, I have mentioned some concerns about Gravatar. As WesternMA points out, Gravatar is the only third-party that has visibility to visitors of this website, and only within the blog pages.
Gravatar is owned by WordPress, the open-source software company that created the software used by this blog. The purpose of Gravatar is the randomized icons by each user that makes it easier to see which comment came from which user. In addition, registered users like me can create a custom icon that reflects my personality.
What this means is that when any person visits any page, my blog server sends the email address of each commentator to Gravatar in order to see if the commenter has a custom avatar. If WordPress wanted, that is an enormously powerful bit of information. It not only tells them what pages you reviewed and when, it also shows the relationships of the other people who read the same blog post and commented on it. Even if you don’t register with Gravatar and never comment on the blog, if you read multiple blogs that use Gravatar, then Gravatar would know the list of blogs that you read – even if they don’t know who you are.
If I was using their anti-spam product (which I am not), the same would be true that word press would see every single comment in real time, even if the blog was private.
Since WordPress is open source and plug-ins are written by many different people, without personally reviewing all of the code, I have to trust that WordPress is not deliberately gathering and leaking information to third parties – but I would be surprised if they don’t. If you read their privacy policy, it says that they will provide information only if a government agency asked for it. That basically says there is no privacy, and no requirement of a legal demand before they would voluntarily provide information if they feel that doing so furthers “the public interest”.
The question on the floor is – should I turn off Gravatar? I could try turning it off for a week and see if it matters to anybody whether there are avatars or not.
Opinions?
So long as my icon doesn’t change to this comedian’s mug shot… oh wait, i thought you had said Gavinatar… never mind.
http://www.rawstory.com/rs/2013/10/23/vice-co-founder-gavin-mcinnes-explodes-at-woman-who-claims-she-can-be-childless-and-happy/
(BTW- Gavin is a regular guest on Kennedy’s show The Independents and is sometimes quite funny.)
Gravtar or Avatar it does help in immediately connecting a post to the personality of the poster. What about the method other sites use wherein each blogger uploads their preferred avatar?
Actually, it was I who mentioned the Gravatar widget (most recently anyway).
Normally, it wouldn’t bother me since I tend to use a generic name/handle and don’t blog on any other sites which use it (AFAIK) … whereas “CC1s121LrBGT” is a much easier name/handle ($tring) to ‘data mine’ and not get too many false positives. 😉
However, you state it uses an EMAIL address, which I do find a bit disconcerting… i.e. more difficult to ‘go Galt’. In that case, I’m probably flagged as ‘right wing extremist’.
Actually, that was an assumption that may not be true. Let me restate it – your avatar (if you do not have a customized one) is based on an algorithm based on your email – so as long as you register in different blogs using the same email, you get the same icon. Foyle used to have a custom icon because he registered his. How it actually figures that out, I’m not sure. WordPress is written in Php, which means the gravatar source code is viewable if I take the time to look at it
okay, here is the non-assumption version after looking at the code.
Remember that the fetching of the icon is done by your browser, not by the web server. The code takes your email address and transforms it into an MD5 “hash” that is 32 characters long. The MD5 hash was created by RSA, one of the companies already implicated in facilitating NSA snooping by deliberately creating weak algorithms.
The hash tag is what is sent to the gravatar web server for it to try to retrieve your custom icon.
While the MD5 hash is technically “encryption”, it really isn’t. If you had a suspected email address, anyone could compute the MD5 hash for that address and prove the connection with certainty. Given the character set limitations of email addresses, it would also be fairly trivial for a super computer to derive the email address used to create a specific MD5 hash.
Can I turn myself into a turnip? I like turnips 🙂
Certainly. Just go to gravatar.com and register and upload a picture of a turnip, and you’re there.
By the way, turnipseed is a great NC surname