Several sources state that there was a leak on October 3, 2020, and people are talking about it just now.
I don’t know anything about this kind of stuff, as well as the actual data that was leaked (names and emails are mentioned, but people say only public data was leaked).
I wonder what exactly happened with this 2 years data leak, if it affects our users (considering Discourse uses Gravatar) and if they should be informed about that.
Discourse uses gravatar just for avatars. The breach might mean that people who had access to the breached data could infer what someone’s discourse email address is.
Discourse doesn’t use gravatar for authentication, so it doesn’t take affect discourse.
So… if my gravatar email leaks, people will trivially be able to connect the email I use at Stack Overflow with gravatar.
Gravatar usage at Discourse is very different, we do not hotlink to gravatar, we download a copy of the avatar and self host. We even resize the images ourselves.