Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 2 min read

Hashed Emails Aren't Anonymous: Use Pairwise IDs Instead

If your sign-in flow stores sha256(lower(email)) and you call that "anonymised", it isn't. A hashed email is a stable, cross-site identifier: every service that hashes the same address gets the same string, and ad-tech "

If your sign-in flow stores sha256(lower(email)) and you call that "anonymised", it isn't. A hashed email is a stable, cross-site identifier: every service that hashes the same address gets the same string, and ad-tech "clean rooms" are built on exactly that join.

I'm building ClientN, so I've spent a lot of time on this question. Here is the short version for developers.

Why hashing doesn't help

  1. Same input, same output. [email protected] hashes to the same value on your site, on a retailer's site and in a data broker's table. Matching is a plain JOIN.
  2. The input space is small. Emails are guessable. Anyone with a list of addresses can hash them and look yours up β€” no "reversing" needed.
  3. Salting per site breaks the join, but you still hold the email. You collected it, so it can leak, be subpoenaed or be shared later.

What actually limits linkability: pairwise identifiers

Give each relying site a different identifier for the same person, derived so that sites cannot correlate them. In ClientN, a user signs in with a passkey (WebAuthn) and each integrated site receives its own anonymous CN- id. Site A's id for a user tells Site B nothing.

What the site gets:

  • a stable id for that site only β€” enough for accounts, sessions, rate limits and bans on your own service;
  • no email and no password to store, so nothing reusable to leak.

Where it fits (and where it doesn't)

  • It only applies on sites that integrate it β€” it is not a fix for "all internet privacy".
  • You still need your own abuse controls; a per-site id gives you a key to apply them to without collecting identity.

Try it

Websites are free up to 1,000 logins/month until 2027-03-31. People get a free account (email + passkey) at https://clientn.com/signup.

Verified Human. Still Anonymous. β€” Longer write-up on our blog: https://clientn.com/blog/hashed-emails-arent-anonymous-how-your-login-becomes-an-ad-id

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.