Slashdot can be prone to scaremongering as much as the tabloids. This article is about someone who has found a way to extract email addresses from MicroID hashes on some sites. The idea of Micro ID is that it allows you to associate a user account on a site with an email address without revealing that address. Then sites like ClaimID can verify that you own a given account, as I have done for several. The idea has been criticised, but I think it is useful in a limited way. It is vulnerable to people working out what the email address was if they know your name and can guess what domain it is on. Not too hard in my case as my email is hosted on my own site that I publish in my account profiles. I'm not too bothered about this account as my email address has been heavily spammed anyway for ages. I suspect it may have been harvested from a key server as those publish all email addresses without obfuscation. I would prefer to share my email address openly so that people can easily contact me, but it seems that is not advisable due to others abusing it. As they already do should I be worried?
It seems that others take this threat more seriously as last.fm and digg have stopped using MicroID. This is a shame. identi.ca have handled it better by giving you an option of whether to have a MicroID on your profile page. Perhaps someone can come up with a more secure protocol that does not reveal private information. This is a complex field in which I am not qualified to dabble. Security and encryption are very easy to get wrong.
Whilst looking into this I found that ClaimID was down. This could be a problem for me as I use them for OpenID on a few sites. I wouldn't use it for anything critical or financial, but it saves me having to come up with passwords for every site. As I let Firefox save my OpenID password I rarely have to enter it. This makes me slightly more secure if some site tries to redirect me to a clone of the log-in screen as that would not have my details.
I've had a GPG public key for years, but have not used it for much. Very few people I know will send me encrypted emails. I keep expecting spammers to start doing that as a way around spam filters. I'm not sure it is a big enough target for them. The only site that has used my public key to verify my identity is Biglumber that deals with that topic anyway.
I'm generally interested in ways that we can publish personal information so that people can use it to contact us, but still protect our privacy. Is there an answer? Perhaps email is too broken to be of use. Closed systems like Facebook allow messages to be sent with options to block those you don't know, but are not open enough for general usage.