-
Website
http://blog.phanfare.com -
Original page
http://blog.phanfare.com/2009/05/privacy-the-principle-of-least-surprise/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Rich DeAugustinis
2 comments · 1 points
-
Andrew Erlichson
2 comments · 1 points
-
Oi Torpedo
2 comments · 1 points
-
hayles
3 comments · 1 points
-
Vinod
2 comments · 2 points
-
-
Popular Threads
-
HD Video has Landed at Phanfare
4 weeks ago · 22 comments
-
The case for purpose-built devices
1 week ago · 1 comment
-
Other Goodies in HD Video Release
3 weeks ago · 1 comment
-
HD Video has Landed at Phanfare
I never signed up at gravatar, and it was certainly not clear that signing me up for one service opted me in to the other. I created a blog on wordpress and now wordpress is giving up my identity without notice to millions of wordpress blogs. This is privacy 101.
You need to look at how this works. When I go to any blog that is hosted by wordpress, even when that blog is a completely separate domain, and I post a comment, even if I deliberately use a false email address and name, then my photo will appear.
They do this by placing a link to gravatar.com or wordpress into the blog and because I have logged into wordpress from that browser, it passes my cookie to wordpress and they give up my identity.
It would not be difficult for wordpress to fix this. In the comment field. It just needs to say
"Wordpress Blog: You are logged in as Andrew Erlichson" Logout.
In fact, given that Wordpress knew who I was on the page and planned to give my identity up, why did the even make me type an email address and name to post the comment?
Disqus does this right. Right now, I am t yping a comment into this blog and I see my photo and a note that says "logged in as erlichson" and a link that says "Logout from DISQUS"