<?xml version="1.0" encoding="utf-8"?>
<feed xml:lang="en-us" xmlns="http://www.w3.org/2005/Atom"><title>Simon Willison's Weblog: commentspam</title><link href="http://simonwillison.net/" rel="alternate"/><link href="http://simonwillison.net/tags/commentspam.atom" rel="self"/><id>http://simonwillison.net/</id><updated>2008-06-20T18:55:38+00:00</updated><author><name>Simon Willison</name></author><entry><title>Quoting ator_fighting_eagle</title><link href="https://simonwillison.net/2008/Jun/20/redditcom/#atom-tag" rel="alternate"/><published>2008-06-20T18:55:38+00:00</published><updated>2008-06-20T18:55:38+00:00</updated><id>https://simonwillison.net/2008/Jun/20/redditcom/#atom-tag</id><summary type="html">
    &lt;blockquote cite="http://www.reddit.com/info/6o6gp/comments/c04f37e"&gt;&lt;p&gt;This is the new blog-spam. [...] 'web design company' takes the highest ranking comment from reddit, and posts it on the site that the original comment is based on. [...] Neat eh? They get to have links on a site that won't get blog-spam filtered, because the comment is 'relevant', since the comment originates from a comment thread about the site.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p class="cite"&gt;&amp;mdash; &lt;a href="http://www.reddit.com/info/6o6gp/comments/c04f37e"&gt;ator_fighting_eagle&lt;/a&gt;&lt;/p&gt;

    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/commentspam"&gt;commentspam&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/reddit"&gt;reddit&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/spam"&gt;spam&lt;/a&gt;&lt;/p&gt;



</summary><category term="commentspam"/><category term="reddit"/><category term="spam"/></entry><entry><title>Introducing http:BL</title><link href="https://simonwillison.net/2007/Apr/25/httpbl/#atom-tag" rel="alternate"/><published>2007-04-25T23:39:55+00:00</published><updated>2007-04-25T23:39:55+00:00</updated><id>https://simonwillison.net/2007/Apr/25/httpbl/#atom-tag</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://www.projecthoneypot.org/5days_wednesday.php"&gt;Introducing http:BL&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
Project Honey Pot announce a new blacklist service for blocking comment spammers and e-mail spiders using information from their network of honey pots.

    &lt;p&gt;&lt;small&gt;&lt;/small&gt;Via &lt;a href="http://www.jacobian.org/reading/"&gt;Jacob Kaplan-Moss&lt;/a&gt;&lt;/small&gt;&lt;/p&gt;


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/blacklist"&gt;blacklist&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/commentspam"&gt;commentspam&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/honeypot"&gt;honeypot&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/security"&gt;security&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/spam"&gt;spam&lt;/a&gt;&lt;/p&gt;



</summary><category term="blacklist"/><category term="commentspam"/><category term="honeypot"/><category term="security"/><category term="spam"/></entry><entry><title>Stopping spambots with hashes and honeypots</title><link href="https://simonwillison.net/2007/Jan/23/spambots/#atom-tag" rel="alternate"/><published>2007-01-23T13:39:15+00:00</published><updated>2007-01-23T13:39:15+00:00</updated><id>https://simonwillison.net/2007/Jan/23/spambots/#atom-tag</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://www.nedbatchelder.com/text/stopbots.html"&gt;Stopping spambots with hashes and honeypots&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
Ned’s analysis of how spambots work, along with some relatively simple tricks that should fool most of them.


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/commentspam"&gt;commentspam&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/hashing"&gt;hashing&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/ned-batchelder"&gt;ned-batchelder&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/spam"&gt;spam&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/spambots"&gt;spambots&lt;/a&gt;&lt;/p&gt;



</summary><category term="commentspam"/><category term="hashing"/><category term="ned-batchelder"/><category term="spam"/><category term="spambots"/></entry><entry><title>Social whitelisting with OpenID</title><link href="https://simonwillison.net/2007/Jan/22/whitelisting/#atom-tag" rel="alternate"/><published>2007-01-22T03:01:02+00:00</published><updated>2007-01-22T03:01:02+00:00</updated><id>https://simonwillison.net/2007/Jan/22/whitelisting/#atom-tag</id><summary type="html">
    &lt;p id="p-0"&gt;A key feature of OpenID is that it provides a globally unique identifier for every user, no matter what site or service they are using on the Web.&lt;/p&gt;

&lt;p id="p-1"&gt;This gives us a powerful tool to fight comment spam. If someone has logged in with an OpenID &lt;em&gt;and&lt;/em&gt; we are confident that they are not a spammer (remember, spammers can create OpenIDs too) we can add them to a whitelist, allowing their comments to skip any moderation step or spam guard that we might have in place.&lt;/p&gt;

&lt;p id="p-2"&gt;This weblog has a comment spam detection system  based on simple heuristics. Comments are assigned a score; if the score exceeds a certain level the comment is placed in a queue for moderation. As of today, one of the heuristics is "does the comment author have an OpenID that is on the whitelist". I've populated my whitelist with the OpenIDs of people who have posted two or more useful comments  and do not appear to be using an &lt;a href="http://www.jkg.in/openid/"&gt;anonymous provider&lt;/a&gt;. I'll be adding to it regularly in the future.&lt;/p&gt;

&lt;p id="p-3"&gt;Here comes the social part: I'm &lt;a href="http://simonwillison.net/comments/whitelist/"&gt;sharing my whitelist&lt;/a&gt;. If you run your own OpenID-enabled weblog you are welcome to include my whitelist in your comment spam heuristics. If you publish your own whitelist, I will happily do the same.&lt;/p&gt;

&lt;p id="p-4"&gt;Social whitelisting benefits from being de-centralised, just like OpenID. If I find that you have whitelisted a spammer, I can unsubscribe from your whitelist. There's no central authority or point of failure.&lt;/p&gt;

&lt;p id="p-5"&gt;Long-time readers may be feeling a strong sense of deja-vu. Way back in September 2003, &lt;a href="http://simonwillison.net/2003/Sep/2/blacklisting/"&gt;I proposed shared comment blacklists&lt;/a&gt; as a solution to weblog comment spam. The idea was simple: every time you delete a spam comment, you add the link it was advertising to a public blacklist. Other blogs could then subscribe to your blacklist and block any new comments advertising the same site.&lt;/p&gt;

&lt;p id="p-6"&gt;The blacklisting idea was flawed from the very start. It was a classic example of Marcus J. Ranum's &lt;a href="http://www.ranum.com/security/computer_security/editorials/dumb/" title="The Six Dumbest Ideas in Computer Security"&gt;number one dumbest idea in computer security&lt;/a&gt;: Default Permit. Spam blacklists assume that if we don't know a link is bad, it's good. Spammers can create new bad links far faster than we can blacklist them.&lt;/p&gt;

&lt;p id="p-7"&gt;Here's Ranum's suggested alternative:&lt;/p&gt;

&lt;blockquote cite="http://www.ranum.com/security/computer_security/editorials/dumb/"&gt;&lt;p id="p-8"&gt;The opposite of "Default Permit" is "Default Deny" and it is a really good idea. It takes dedication, thought, and understanding to implement a "Default Deny" policy, which is why it is so seldom done. It's not that much harder to do than "Default Permit" but you'll sleep much better at night.&lt;/p&gt;&lt;/blockquote&gt;

&lt;p id="p-9"&gt;Social whitelisting uses Default Deny. As such, I believe it has a much higher chance of making a useful impact on the comment spam problem.&lt;/p&gt;

&lt;p id="p-10"&gt;&lt;strong&gt;Update:&lt;/strong&gt; I should have mentioned that this idea developed over a number of discussions with &lt;a href="http://www.plasticbag.org/"&gt;Tom Coates&lt;/a&gt;, which totally slipped my mind when I was writing it up at 3am.&lt;/p&gt;
    
        &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/commentspam"&gt;commentspam&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/moderation"&gt;moderation&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/openid"&gt;openid&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/tom-coates"&gt;tom-coates&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/whitelisting"&gt;whitelisting&lt;/a&gt;&lt;/p&gt;
    

</summary><category term="commentspam"/><category term="moderation"/><category term="openid"/><category term="tom-coates"/><category term="whitelisting"/></entry></feed>