Third-Party connections to gravatar.com in Jitsi and OpenProject
Issue/Feedback/Need
During testing we saw OpenDesk establish connections to gravatar.com.
Apparently, Jitsi and OpenProject support Gravatar and enable it by default.
As that is a third-party connection and not really required for OpenDesk to work, we would prefer to have it disabled by default in OpenDesk. (So OpenDesk should overwrite the upstream defaults in that case.)
Possible Solution/Recommendation
I looked up how Gravatar support is handled by Jitsi and OpenProject upstream.
- Jitsi: this part of the config should disable it
- OpenProject: seems like it can be disabled via GUI or environment variable
Classification
Priority/Severity
Prio:medium
Type
Usability Issue (Privacy Improvement)
Source/Methods
Usability Tests (including Network Traffic Analysis)