We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
It seems the rationale is that it's possible to reverse-engineer the e-mail address from the md5 hash.
Automattic/wp-calypso#87886
I think FA is using md5 instead of sha256.
At some point, gravatar started recommending sha256, as their docs say to use it:
https://docs.gravatar.com/api/avatars/hash/