Site news: Comment entry changed once more

by Volker Weber

In an effort to avoid comment spam I have changed the comment entry system once more. As explained in the previous post, the old solution did not scale.

I have now designed a two step process. If you want to post a comment, you will first have to go to a preview screen that contains the security code and then post from there. This has two benefits:

  1. You get to see your comment as it would be posted. Check for embarrassing typos.
  2. The site has to generate the security code only for a few dozen comments a day and not for thousands of page views.

Update: I suggest you load this stylesheet once and refresh the browser window before proceeding.

What do you think? Give it a try.

Comments

Works like a charm. But then, this was to be expected.
And it's still slow as hell. But then, this was to be expected, too ;-)

Still the same old server. Possible better in two days.

Simple and clever and a solution to two problems.
In Italy they say "catching two pigeons with one bait",...

The English version is "kill two birds with one stone". And In German you would "zwei Fliegen mit einer Klappe schlagen" (for some reason Germans seem to prefer to kill/catch flies instead of birds)

Good solution. And the mandatory preview is generally a good idea too. I really do wonder, why similar systems haven't been implemented (as standard) with other blogging systems. It seems such an easy way to keep out spam bots ...

But - and I don't know, if this really is a problem right now - the pictures your tool is generating seem to contain not much noise. Wouldn't it be easy for a spammer to include a little character recognition into its bot?

Nothing is impossible for the man who doesn't have to do it himself.
— A.H. Weiler

Teaching a class in Management of Information Security we tell our students, there is no 100% security, at least not to an affordable or reasonable price. You always have to figure out how high you need to raise the bar to be comfortable. That is usually referred to as "risk management". I guess in this case the bar is high enough with the produced images as they are.
After all, you don't have to run faster than your predator, you only have to run faster than the slowest prey...

Ragnar Schierholz, 2004-11-03 10:07

If this appears this seems to work nice ;-)
I just wonder if forcing the preview wouldn't be enough. Or would it be just a too easy step for spammers to include a "second click" into their scripts?

Spammers don't click. They call the script that posts the comment. That script is now locked with the captcha controller and the preview page gives you the key to the lock.

Nice solution, works well. Definitely makes sense to load up the graphic when you know someone is making a comment rather than on every permalink page. I caught a typo too!

Testing, Testing...
works fine for me... but I feel sincerely flattered that you are moving to a faster server because of our comments.;-)

Martin Forisch, 2004-11-03 14:23

Post a comment











Shall I remember this for you?




Use your full name and a working email address. Unless you want your comment to be removed. No kidding.



Recent comments

Ben Poole on It has only been less than two hours at 09:44
Frank L. Quednau on It has only been less than two hours at 09:29
Martin Hiegl on It has only been less than two hours at 08:27
Stephan H. Wissel on Notes.ini parameter RunFaster=1 is finally here at 05:24
Volker Weber on It has only been less than two hours at 01:33
Thomas "Duffbert" Duff on It has only been less than two hours at 01:26
Chris Linfoot on Planet Lotus not picking up Christopher's feed at 21:56
Yancy Lent on Planet Lotus not picking up Christopher's feed at 19:48
Bruce Elgort on Robin Bloor: Why Google Chrome Will Dominate at 18:51
Mac Guidera on Planet Lotus not picking up Christopher's feed at 16:04
Kevan Emmott on 824 Chrome users so far today at 15:56
Chris Linfoot on Planet Lotus not picking up Christopher's feed at 14:54
Lars Berntrop-Bos on Planet Lotus not picking up Christopher's feed at 13:12
Andreas Braukmann on 824 Chrome users so far today at 11:33
Nick Daisley on Robin Bloor: Why Google Chrome Will Dominate at 10:14
Chris Linfoot on Planet Lotus not picking up Christopher's feed at 09:42
Alper Iseri on 824 Chrome users so far today at 09:38
Jean Pierre Wenzel on 824 Chrome users so far today at 08:37
Jan-Piet Mens on Robin Bloor: Why Google Chrome Will Dominate at 08:26
Benjamin Stein on Synchronizing iPhone with ... Lotus Notes at 07:18
Greg Walrath on Party like it's 2008 at 06:56
Andy Brunner on Party like it's 2008 at 05:41
Michelle O'Rorke on Synchronizing iPhone with ... Lotus Notes at 05:01
Arthur Fontaine on Chrome in the wild at 03:26
Yancy Lent on Planet Lotus not picking up Christopher's feed at 02:15

Ceci n'est pas un blog

vowe.net is a personal website published by Volker Weber a.k.a. vowe. I am an author, consultant and systems architect based in Darmstadt, Germany.

rss Click here to subscribe

Hello

About me
Contact
Publications
Certificates
Frequently asked questions

Twitter Updates

More >

Poll

Can you bring a camera phone to work?

Getting poll results. Please wait...

Local time is 10:20

visitors.gif
176 visitors online

News

Other sources of news, imported into my own format to make them more accessible:

Heise Online
Schlagzeilen
Weather

Archives

As most of my articles roll off the front page rather quickly, I am making an archive of previous posts available here. You can also use the handy search box at the top of the page if you are looking for something particular.

Last 30 days
More archives

Got the T-shirt?

Got the T-shirt?
Are you buying from the US?

Systems Architecture

This site runs on an Apache web server on top of the Linux operating system. The content is managed with MovableType which is implemented in Perl. Last but not least the HTML code your browser sees is put together with PHP.

© 1992-2008 Volker Weber.
All Rights Reserved.

Impressum