Bram Moolenaar wrote:
> So I created a page that can be edited:
> http://groups.google.com/group/vim_dev/web/vim-patches
> 
> I have added the 2008 Google Summer of Code entries as an example.
> If you want people to know your Vim patch, please add it here!
> 
> This should be an overview, with links to where more 
> information can be found.  Add just enough information for 
> people to know if this is an interesting patch for them.
> 
> To make the page editable I had to enable adding and editing 
> pages for group members.  That probably means we will get 
> some spam.  Please remove it when you see it.

Can't we use the wiki for this? The wiki has an excellent history, and methods 
to
undo spam that are easy and bullet proof. In addition, the "recent changes" 
page on
the wiki is regularly patrolled: all edits are checked.

By contrast, the Google web pages are a time bomb. A common attack leaves the 
web
page unchanged in appearance, but alters the link targets to MALWARE SITES that 
try
to entice users to install trojans, and which may try to exploit browser bugs to
auto-install malware.

This is not a theoretical attack: IT HAS HAPPENED to vim_use and vim_mac. In one
case, it was quite easy to revert the attack, but in another case some glitch
occurred and half-an-hour's messing around was required to clean up. I think 
that
was a bug in Google Groups, and not something clever that the spammer had done.
However, there are reliable reports that spammers put stuff in spam pages that 
make
it hard to edit or delete the page.

Here is a claimed example (browsing the group shows that author Virden gives
excellent advice):
http://groups.google.com/group/Google-Groups-Basics/browse_thread/thread/3c29774c081
aaa03/

Here is more info about attacker polartest:
http://groups.google.com/groups/search?qt_s=1&q=polartest

John


--~--~---------~--~----~------------~-------~--~----~
You received this message from the "vim_dev" maillist.
For more information, visit http://www.vim.org/maillist.php
-~----------~----~----~----~------~----~------~--~---

Raspunde prin e-mail lui