DEV Community

Amr Abumady
Amr Abumady

Posted on Originally published at clientn.com

Hashed Emails Aren't Anonymous: Use Pairwise IDs Instead

If your sign-in flow stores sha256(lower(email)) and you call that "anonymised", it isn't. A hashed email is a stable, cross-site identifier: every service that hashes the same address gets the same string, and ad-tech "clean rooms" are built on exactly that join.

I'm building ClientN, so I've spent a lot of time on this question. Here is the short version for developers.

Why hashing doesn't help

  1. Same input, same output. alice@example.com hashes to the same value on your site, on a retailer's site and in a data broker's table. Matching is a plain JOIN.
  2. The input space is small. Emails are guessable. Anyone with a list of addresses can hash them and look yours up — no "reversing" needed.
  3. Salting per site breaks the join, but you still hold the email. You collected it, so it can leak, be subpoenaed or be shared later.

What actually limits linkability: pairwise identifiers

Give each relying site a different identifier for the same person, derived so that sites cannot correlate them. In ClientN, a user signs in with a passkey (WebAuthn) and each integrated site receives its own anonymous CN- id. Site A's id for a user tells Site B nothing.

What the site gets:

  • a stable id for that site only — enough for accounts, sessions, rate limits and bans on your own service;
  • no email and no password to store, so nothing reusable to leak.

Where it fits (and where it doesn't)

  • It only applies on sites that integrate it — it is not a fix for "all internet privacy".
  • You still need your own abuse controls; a per-site id gives you a key to apply them to without collecting identity.

Try it

Websites are free up to 1,000 logins/month until 2027-03-31. People get a free account (email + passkey) at https://clientn.com/signup.

Verified Human. Still Anonymous. — Longer write-up on our blog: https://clientn.com/blog/hashed-emails-arent-anonymous-how-your-login-becomes-an-ad-id

Top comments (1)

Collapse
 
omyvnss profile image
Om Yaduvanshi •

solid explainer. honest question on pairwise ids: the email has to live somewhere for account recovery, so who holds it? if the identity provider keeps it, correlation didn't disappear, it moved.