1 |
There are only 4 billion to reverse, not that hard really with a rainbow |
2 |
table... |
3 |
|
4 |
On Thu, 21 May 2020 at 13:08, Michał Górny <mgorny@g.o> wrote: |
5 |
|
6 |
> On Thu, 2020-05-21 at 13:57 +0200, Ulrich Mueller wrote: |
7 |
> > > > > > > On Thu, 21 May 2020, Robert Bridge wrote: |
8 |
> > > On Thu, 21 May 2020 at 09:47, Michał Górny <mgorny@g.o> wrote: |
9 |
> > > > Option 1: IP-based limiting |
10 |
> > > > =========================== |
11 |
> > > > |
12 |
> > > Preface this with IANAL, check with your own legal counsel... |
13 |
> > > While IP address based methods might be attractive technically, do |
14 |
> > > remember that an IP address is considered Personally Identifiable in |
15 |
> > > European Data Protection law. |
16 |
> > > The fact submissions require an action by the user will probably be |
17 |
> > > sufficient to be explicit consent, any system storing these details |
18 |
> should |
19 |
> > > allow for the use to revoke their consent: If you collect anything |
20 |
> > > personally identifiable, you will need to provide a mechanism for |
21 |
> users to |
22 |
> > > request the removal of all their submissions. |
23 |
> > > Tread carefully with this project. :) |
24 |
> > |
25 |
> > You don't have to store any IP addresses, you can store a cryptographic |
26 |
> > hash like their b2sum (salted if necessary). |
27 |
> > |
28 |
> |
29 |
> Yes, this is as great as storing hashes of phone numbers ;-). |
30 |
> |
31 |
> -- |
32 |
> Best regards, |
33 |
> Michał Górny |
34 |
> |
35 |
> |