In what world is a public email sensitive PII, mate? Sure, “never post anything on the internet ever” is the best OPSEC posture by default, but this user is a clearly-experienced self-hoster who understands the risks and consequences of what they’re doing.
It’s listed as their whois domain contact, and anyone with OSINT chops can find a long-term email tied to a custom domain with enumeration tools + breach data. Why hide it?
Email is an unique identifier, so whatever content and metadata goes along it is identified. For example now we know accounts lena and gregor use the same device and most probably belong to the same person.
You could've also simply gone through my post history and seen that I switched accounts like two years ago. Both of my accounts were also admins of my instance at some point.
Don't post screenshots with personal identifyable information...
In what world is a public email sensitive PII, mate? Sure, “never post anything on the internet ever” is the best OPSEC posture by default, but this user is a clearly-experienced self-hoster who understands the risks and consequences of what they’re doing.
It’s listed as their whois domain contact, and anyone with OSINT chops can find a long-term email tied to a custom domain with enumeration tools + breach data. Why hide it?
Email is an unique identifier, so whatever content and metadata goes along it is identified. For example now we know accounts lena and gregor use the same device and most probably belong to the same person.
You could've also simply gone through my post history and seen that I switched accounts like two years ago. Both of my accounts were also admins of my instance at some point.
I meant it as an example. You decide what information you want to make public.