Re: comment poster privacy issue?
Igor Leturia <[email protected]>
| Newsgroups | gmane.comp.python.zope.coreblog.english |
|---|---|
| Message-ID | <[email protected]> |
Frank Scholz wrote: Hi, Luistxo Fernandez ([email protected] ) schrieb: However, I'm not so convinced with that form. Anyone can fill that signing Bill Gates, [email protected] and that's what our friend Erral (also present at this list) will get... and, I'm sorry to pick on Igors work like this, Don't worry, any constructive criticism is appreciated, and I know my work is not perfect, your advice will help making it better. one could also easily build a script walking over this site, following the link and sending every poster one or many emails with any form of content and all emails are originated from Igors site and perhaps even with his real email address collected at Gmame or somewhere in Google. That's right. And in fact, someone has done it, because I'm receiving spam sent through the contact form of my blog! The only way to avoid this, I think, is using some captcha method, as Luistxo pointed out. But I still think it has some advantages: - Firstly, such a script has to be custom made for my site, I mean, the spammer has to realize that there is a non-spam protection in the site, manually follow the poster's link, annotate the names of the form's fields and make the script. And this work for every site... The effort is much bigger than just having a robot collecting mailto references, don't you think? - Secondly, the comment poster might be receiving some spam through our site, but at least his address is never compromised and put in the hands of spammers. - Thirdly, as all the traffic goes through our server, if we see spam sent through it, we can implement filters that would block spam. I would rather prefer a system like the one at Gmane, with the email encoded as a curious image. I'm unsure about this, as these captcha pictures violate section 508 - barrier free accessibility. (Don't know whether the equivalent EU decree is on the way or already passed.) Which makes it nearly impossible then to integrate COREBlog in an environment where this is an issue. And I'm not sure, whether the Gmame solution with using a hashed email-address with an acknowledgment will really solve that matter, plus imho it is an obstruction that may prevent posters due to its fussiness. To the second I read about several methods to break computer generated captchas, so these things will only help as long as the other side didn't take it further. One example: http://www.cs.berkeley.edu/~mori/gimpy/gimpy.html Human generated captchas - what is the opposite of "cold", what colour has the block on the left - are harder, but these quiz- or puzzle captchas irritate sometimes "normal" users and perhaps might even generate a new job description - SPAM bot trainer. And if there are only a few variants, such a trained bot could still break its way through. Anyway, I don't think spammers will get into that. Getting e-mail addresses by automatic robots and sending lots of e-mail at once is an easy and cheap work. But if they have to start guessing and breaking each site's protection method just to be able to send a few spam messages, they'll give up, it's just not worth the time and the cost... Considering this, and that the uniqueness of the blogosphere is the linking in between, I don't think that there is a real need for a private messaging within a blog-system. As then we could use any arbitrary forum-software. If somebody leaves its email, it should be visible for the blog-owner, as most of the times the comment corresponds to a blog entry. I think that giving a reader the possibility to contact privately with a comment poster is interesting. And there is still the option, that someone can leave his email address in the comment itself. Well, if we say 'if you want people to be able to contact with you, write your address in the comment', no one concerned about spam would do it. And if he does and his address is captured, it's his fault, not the blog's owner's. ------------------------------------------------------ Igor Leturia Azkarate Elhuyar I+G+B Zelai Haundi kalea, 3 Osinalde industrialdea 20170 Usurbil (+34) 943 36 30 40 [email protected] / www.elhuyar.org _______________________________________________ COREblog-en mailing list COREblog-en-/9qXvnWia/9Wk0Htik3J/[email protected] http://postaria.com/cgi-bin/mailman/listinfo/coreblog-en Unsubscription writing to coreblog-en-leave-/9qXvnWia/9Wk0Htik3J/[email protected]