Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You might get more milage in if the avatars are unique to the user viewing them rather than identical between users. If the nonce/salt used in generation it itself secure then it'd be phrohibity difficult for adversaries to force a collision without obvious detection, doubly so in communities.


"This is what it would look like if your randomart avatar conceived a child with the repo owner's randomart avatar."


That's a good idea! Although, it could still potentially backfire for the same reason as scrypt; now if an adversary is able to obtain your nonce, they are much more likely to fool you.

I guess my broader point here (which I neglected to mention in the OP) is that we already have an excellent means of verifying identities: cryptographic signatures. Avatars are fine, but our interfaces need to make it clear that an avatar is just a costume, not a fingerprint. The Hard Problem, as we all know, is tying real-world people (and objects) to virtual-world pubkeys. If we can manage that, the rest is moot.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: