Frank Scholz wrote:
Hi,
Luistxo Fernandez ([EMAIL PROTECTED]) schrieb:
  
However, I'm not so convinced with that form. Anyone can fill that signing
Bill Gates, [EMAIL PROTECTED] and that's what our friend Erral (also present
at this list) will get...
    
and, I'm sorry to pick on Igors work like this,
  
Don't worry, any constructive criticism is appreciated, and I know my work is not perfect, your advice will help making it better.
one could also easily build a script walking
over this site, following the link and sending
every poster one or many emails with any form
of content and all emails are originated from
Igors site and perhaps even with his real email
address collected at Gmame or somewhere in Google.
  
That's right. And in fact, someone has done it, because I'm receiving spam sent through the contact form of my blog! The only way to avoid this, I think, is using some captcha method, as Luistxo pointed out.
But I still think it has some advantages:
- Firstly, such a script has to be custom made for my site, I mean, the spammer has to realize that there is a non-spam protection in the site, manually follow the poster's link, annotate the names of the form's fields and make the script. And this work for every site... The effort is much bigger than just having a robot collecting mailto references, don't you think?
- Secondly, the comment poster might be receiving some spam through our site, but at least his address is never compromised and put in the hands of spammers.
- Thirdly, as all the traffic goes through our server, if we see spam sent through it, we can implement filters that would block spam.
I would rather prefer a system like the one at
Gmane, with the email encoded as a curious image.
    
I'm unsure about this, as these captcha pictures
violate section 508 - barrier free accessibility.
(Don't know whether the equivalent EU decree is on
the way or already passed.)
Which makes it nearly impossible then to integrate
COREBlog in an environment where this is an issue.
And I'm not sure, whether the Gmame solution with
using a hashed email-address with an acknowledgment
will really solve that matter, plus imho it is an
obstruction that may prevent posters due to its
fussiness.
To the second I read about several methods to break
computer generated captchas, so these things will
only help as long as the other side didn't take
it further.
One example:
http://www.cs.berkeley.edu/~mori/gimpy/gimpy.html
Human generated captchas - what is the opposite
of "cold", what colour has the block on the left -
are harder, but these quiz- or puzzle captchas
irritate sometimes "normal" users and perhaps
might even generate a new job description
- SPAM bot trainer. And if there are only
a few variants, such a trained bot could
still break its way through.
  
Anyway, I don't think spammers will get into that. Getting e-mail addresses by automatic robots and sending lots of e-mail at once is an easy and cheap work. But if they have to start guessing and breaking each site's protection method just to be able to send a few spam messages, they'll give up, it's just not worth the time and the cost...
Considering this, and that the uniqueness of the
blogosphere is the linking in between, I don't think
that there is a real need for a private messaging
within a blog-system. As then we could use any
arbitrary forum-software. If somebody leaves
its email, it should be visible for the blog-owner,
as most of the times the comment corresponds to a
blog entry.
I think that giving a reader the possibility to contact privately with a comment poster is interesting.
 And there is still the option, that
someone can leave his email address in the comment
itself.
  
Well, if we say 'if you want people to be able to contact with you, write your address in the comment', no one concerned about spam would do it. And if he does and his address is captured, it's his fault, not the blog's owner's.


------------------------------------------------------
Igor Leturia Azkarate
Elhuyar I+G+B
Zelai Haundi kalea, 3
Osinalde industrialdea
20170 Usurbil
(+34) 943 36 30 40
[EMAIL PROTECTED] / www.elhuyar.org
_______________________________________________
COREblog-en mailing list
[email protected]
http://postaria.com/cgi-bin/mailman/listinfo/coreblog-en
Unsubscription writing to [EMAIL PROTECTED]

Reply via email to