头像会抓什么痒?
这是一个非常严肃的问题:我在这里看到了很多关于 gravatars 的帖子,但我找不到并回答这个问题:gravatars 应该解决什么计算机识别/身份验证(?)问题(如果有的话)?
维基百科条目和官方网站都不是很有用。官网提到了一张“全球独一无二”的图片。独特在什么意义上?据我所知,只有哈希值是唯一的:两个人可以拥有两张看起来非常相似的图片,即使不相同。
请注意,这个问题并不是关于 gravatars 无疑会导致哪些问题(例如泄露 10% 的 stackoverflow.com 帐户电子邮件地址,如此处讨论的: "gravatars 可以泄露电子邮件地址" ) 但是 gravatars 应该考虑哪些身份验证(?)问题(如果有)解决?
我们的目标只是拥有一个很酷/有趣/可爱的图标并通过将其存储在远程网站上来节省带宽,还是还有更多,比如提供我完全缺失的真正的身份验证目的?
请注意,我对它们没有任何反对意见,并且发现它们相当酷,但我只是很难弄清楚它们的目的是什么,以及我是否应该在我正在开发的网络应用程序中关心它们。
This is a very serious question: I've seen lots of threads here about gravatars but I couldn't find and answer to this question: what computer identification/authentication (?) problem, if any, are gravatars supposed to solve?
Neither the Wikipedia entry nor the official website are very useful. The official website mentions a "globally unique" picture. Unique in what sense? As far as I can see it's only the hash that is unique: two persons can have two pictures looking very similar if not identical.
Note that this question is not about which problems do gravatars unarguably cause (like leaking 10% of the stackoverflow.com accounts email addresses like discussed here : "gravatars can leak email adresses" ) but about which authentication (?) problems, if any, are gravatars supposed to solve?
Is the goal just to have a cool/funny/cute icon and save bandwith by having it stored on a remote website or is there more to it, like serving a real authentication purpose which I'd be completely missing?
Note that I've got nothing against them and find them rather cool, but I'm just having a hard time figuring out what their purpose is and if I should care or not about them in the webapps I'm developping.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(4)
这不是安全问题。目的只是为了向人们提供图片,以便 (1) 在讨论中轻松识别他们(除非发生极不可能的碰撞); (2) 在站点之间是持久的; (3) 不需要个人付出任何边际努力。
我的印象是,它们写得相当快且有趣,并且比创建者预期的要成功得多 - 因此存在错误/问题。但我的想法可能是错的。
It's not a security thing. The purpose is just to give people pictures which (1) identify them easily in a discussion (barring very-unlikely collisions); (2) are persistent between sites; and (3) require no marginal effort whatsoever on the individual's part.
My impression is that they were written rather fast and for fun, and were way more successful than the creators anticipated - hence the bugs/issues. But I could be wrong about that.
我喜欢它们是因为它们很方便。与 OpenID 和相关的登录方法一起,上传个人资料图片只是我在注册新网站时需要执行的一步。
I like them for their convenience. Along with OpenID and associated login methods, uploading a profile picture is just one less step I need to take when signing up to a new website.
Gravatar 主页非常简洁地解释了这一点:
The Gravatar home page explains it quite succinctly:
CPAN 搜索会自动查找与作者的 cpan.org 地址关联的头像,如我的作者页面。但是,该网站不必包含任何上传或更改图片的功能,而且我可以将同一张图片用于其他服务。我可以同时更改所有这些,而无需访问每个站点。
CPAN Search automatically looks for a gravatar associated with an author's cpan.org address, as you see in my author page. The website, however, doesn't have to include any features for me to upload or change a picture, and I can use the same picture for other services. I can simultaneously change all of them without visiting each site.