https://buy-zithromax.online buy kamagra usa https://antibiotics.top buy stromectol online https://deutschland-doxycycline.com https://ivermectin-apotheke.com kaufen cialis https://2-pharmaceuticals.com buy antibiotics online Online Pharmacy vermectin apotheke buy stromectol europe buy zithromax online https://kaufen-cialis.com levitra usa https://stromectol-apotheke.com buy doxycycline online https://buy-ivermectin.online https://stromectol-europe.com stromectol apotheke https://buyamoxil24x7.online deutschland doxycycline https://buy-stromectol.online https://doxycycline365.online https://levitra-usa.com buy ivermectin online buy amoxil online https://buykamagrausa.net

Collateral damage

Dagnabbit. Cleaning out 382 moderated comment spams, I managed to delete a good dozen legit comments. I’ve reconstructed them, but … dagnabbit. Not what I needed to be doing this…

Dagnabbit. Cleaning out 382 moderated comment spams, I managed to delete a good dozen legit comments. I’ve reconstructed them, but … dagnabbit. Not what I needed to be doing this afternoon.

Spy vs. Spy

I don’t know if it’s because all the hackers and spyware types are busy either focusing on Micro$oft’s new offerings, or else building Ominous Rootkits of DOOM, but I just…

I don’t know if it’s because all the hackers and spyware types are busy either focusing on Micro$oft’s new offerings, or else building Ominous Rootkits of DOOM, but I just ran my bi-weekly spyware sweep with AdAware and Spybot S&D and …

Nada. Nothing found.

It’s quiet … too quiet …

Whither (wither?) Trackback?

A few years back, MovableType introduced Trackbacks. The idea is that if you (from a Trackback-enabled blogging package) included a link a post to a page which had Trackback code,…

A few years back, MovableType introduced Trackbacks. The idea is that if you (from a Trackback-enabled blogging package) included a link a post to a page which had Trackback code, that page would get a pinged database entry indicating the link and a snippet of it. Thus, you could see if someone linked to your posts. Sweet.

Of course, it’s something that link spammers can exploit (by sending bogus pings). Though various tools can control that to some extent (MT-Blacklist, for example), it’s not as easily controlled as spam on comments, due to how the Trackback system is set up (in MT, at least). And so, increasingly, I’ve seen people dropping Trackbacks from their blogs, and using (if they use anything) other, less hackable (and less powerful, IMO) solutions, as Les enumerates.

Which is a shame, because TBs are good stuff, both as a convenient way to see who’s commented on something you said (and removing the need for “I had comments on this, but they were too long, so I put them on my blog here” comments) and for internal cross-references (as I’ve started doing). I don’t intend to drop them any time soon — the link spam here has been pretty much under control of late, and I certainly hate to let the SOBs win.

That said, I think I am going to add a Technorati (“TR”) link in the comment footer of each post, so that it’s easy to see if there has been commentary on it (which, alas, has to be pulled, rather than getting pushed). That link, in MT, would seem to be:

http://www.technorati.com/cosmos/search.html?rank=&sub=mtcosmos&url=<$MTEntryLink$>

I don’t really “get” the Tagback proposal, though (), and aren’t likely to do anything with it for a while until I do.

Anyway, I’m sorry to see TBs going away, because …

[continued a few hours later, once it’s pointed out that I ended mid-sentence]

… I think, conceptually, they’re pretty keen. Damned spammers …

You can’t win for losing

A rather depressing article from the New York Times implies that one reason why spam continues to rise in numbers is because anti-spam stuff keeps getting better — meaning that…

A rather depressing article from the New York Times implies that one reason why spam continues to rise in numbers is because anti-spam stuff keeps getting better — meaning that spammers have to increase volume to get a profitable amount through, launching ever larger “human wave attacks” up from the trenches and into your computer.

She and others note that filtering software has become particularly adept at catching the vast majority of spam before it ever gets to a user’s in-box. Legitimate e-mail messages do sometimes get caught in such nets – a drawback that generates its own chorus of complaints. But some specialists have also suggested that the overall success of identifying and weeding out junk e-mail from in-boxes may actually help explain the current surge in spam. “The more effective the filtering technology,” Ms. Mitchell said, “the more spam they have to send to get the same dollar rate of return.”

Those rates of return can be staggeringly high (and the costs of entry into the market relatively low). A spammer can often expect to receive anywhere from a 25 percent to a 50 percent commission on any sales of a product that result from a spam campaign, according to a calculus developed by Richi Jennings, an Internet security analyst with Ferris Research, a technology industry consulting firm.

Even if only 2,000 of 200 million recipients of a spam campaign – a single day’s response rate for some spammers – actually go to a merchant’s Web site to purchase a $50 bottle of an herbal supplement, a spammer working at a 25 percent commission will take in $25,000. If a spammer makes use of anonymous virus-enslaved computers to spread the campaign, expenses like bandwidth payments to Internet service providers are low – as is the likelihood of anyone’s tracking down who pushed the “send” button.

And legislative approaches have only driven spammers into overseas havens.

And bulletproof services like Mr. Gillespie’s and another, Buprhost.com, are intent on continuing to offer spam-friendly merchants a haven from antispam complaints, starting at $89 a month.

“If your Web site host receives complaints or discovers that your Web site has been advertised in e-mail broadcasts, they may disconnect your account and shut down your Web site,” explains Buprhost.com, which promises no such disruptions. “The reason we can do this is that we put your Web site in our overseas server where the local law will protect your Web sites.”

Swell.

(via Volokh)

Nothing personal? Nothing personal?

Fascinating … and infuriating … interview with an anonymous comment spammer link spammer search engine optimizer. If you’re affected by this spam, say because you run a blog, or a…

Fascinating … and infuriating … interview with an anonymous comment spammer link spammer search engine optimizer.

If you’re affected by this spam, say because you run a blog, or a website, or like the other 99.9 per cent of Net users just come across the stuff, Sam explain the important thing to remember is it’s nothing personal. They’re not targeting you personally. They’re just exploiting a weakness in a system which blossomed just at the time that Google cracked down on the previous method that spammers used, where huge “link farms” of their own web sites pointed circularly to each other to boost each others’ ranking.

Nothing personal? That’s such a great comfort. Not.

But what about the moral question, that you’re using other peoples’ bandwidth and blog space and abusing it by putting your commercial message there? “The question of morals is one for the individual. While it’s legal, it will continue. It could be argued that a website owner is actually inviting content to their site when they allow comments.”

Yes. Please. Come to my house to argue that. Wait, let me get my baseball bat, first …

“All circuits are busy”

My blog has been only intermittently available this morning, due, so far as I can tell, to some serious spamming. Remarkably, very, very little of the 20k or so got…

My blog has been only intermittently available this morning, due, so far as I can tell, to some serious spamming. Remarkably, very, very little of the 20k or so got through (none to the front page, last I checked), but it’s still leading to “too many connections” errors.

Not much I can do about it at this point, save think uncharitable thoughts.

Spam, spam, spam and phish

Intersting — and alarming — note on how phishers are getting more sophisticated. “Phishing” is an attempt, usually through e-mail, to get you to reveal confidential account information. The most…

Intersting — and alarming — note on how phishers are getting more sophisticated. “Phishing” is an attempt, usually through e-mail, to get you to reveal confidential account information. The most common manifestation of this is an e-mail saying, “Hey, you need to update your account info at [fill in the name of the financial institution]. Click here.”

These sorts of attacks used to be (and, sometimes, still are) crude frauds, with typos and bad writing and all sorts of other tells that it wasn’t, in fact, Citibank trying to contact you. But the phishers are getting more sophisticated.

Phishing attacks have reached 57 million U.S. adults and have compromised at least 122 well-known brands so far, according to several estimates. At the end of 2004, nearly half of those attacks contained some sort of spyware or other malicious code, Trudeau said.

One attack, first documented last month by the Danish security firm Secunia, misdirects Web surfers by modifying a little-known directory in Microsoft Windows machines called a host file. When an Internet user types a Web address into a browser, he is directed instead to a fraudulent site. This technique has shown up in attacks spoofing several South American banks, said Scott Chasin, chief technology officer at MX Logic Inc., a security firm in Denver. The convergence of all of these threats means “we can expect to see some large attacks in the near term,” he said.

Another more ambitious attack targets the domain name servers that act as virtual telephone books, matching domain names with numerical addresses given to each computer on the Internet. If one of those computers is compromised, Internet users who type in www.bankofamerica.com, for example, could be directed to a look-alike site run by identity thieves.

Domain name servers are thought to be tougher to crack, but hackers can find a way in by posing as a company’s tech-support department and asking new employees for their passwords, Trudeau said. Domain-name hijacking is suspected in incidents involving Google Inc., Amazon.com Inc., eBay Germany and HSBC Bank of Brazil, Chasin said.

As a general rule, I ignore (in fact, flag as spam) any messages that come in with a subject line that indicates I have account info that needs updating. That’s because legitimate financial institutions and the like are well aware of this problem, and don’t use such messages.

If such a message does come in from an institution that I actually do business with, I’ll look at it. Anything that requires me to click through in the message to go to a web site, I consider to be a scam.

That all said, there’s not a lot that folks can do about DNS spoofing like the above passage mentions (any more than there’s much you can do about someone who works at a credit card company stealing your data). Just be vigilent, check your statements, and be careful before you click through on anything.

More nofollow musings

One of the critiques re nofollow is that there are so many unprotected blogs out there. However, the development may not be all good news. Commenting on the announcement Jason…

One of the critiques re nofollow is that there are so many unprotected blogs out there.

However, the development may not be all good news. Commenting on the announcement Jason Duke, director at SEO company Strange Logic, said: “I speak with professional link spammers daily and most of them are laughing heartily at this announcement. The reality, as they see it, is that this is a PR exercise by the search engines so they are seen to be doing something to combat the problem.

“They know that for this to work people will have to download and install a new version of their blog software and that the majority of blogs out there are started with the best intentions but then left to rot – and gather link spam.”

Duke added: “I expect to see a huge increase in blog and forum spam rather than a reduction over the coming months.”

SEO companies, btw, are “Search Engine Optimization” firms, consultants that assist other companies in improving their search engine rankings. If that sounds related to what comment spammers try to do … well, it is (though, of course, SEOs can be quite legal).

The question I’d have here, though, how many abandoned blogs are there out there? And, more importantly, how many of them are hosted services, rather than hosted on an individual’s domain? In the cases where a blog is hosted by a service, not only are there monthly charges to discourage just abandoning the thing, but the hosting service can, I imagine, impose the needed changes unless specifically opted out of. The same might be true for “blog hosting” hosts like Blogspot. Since it is in these hosting companies interest to reduce the load burden of comment spam, I can see them taking such steps in the future, as part of their user agreements.

The sites that seem most vulnerable are ones that are downloaded blogging packages on regular hosts. I have no idea what proportion of blogs fall into that category (or, more importantly, what proportion of abandoned blogs), but I don’t expect it’s the majority, or even a plurality. Most folks who start then abandon blogs do so, I suspect, on on “free” systems, and the hosts of those will, as noted, have an incentive to push for anything that reduces comment spam.

Will there remain some sites that are unprotected, the proverbial broken window on the street? Sure. Will that provide enough of a boost (especially given that such sites are not likely to have high PR to begin with, and thus not give high PR in return) to link spammers to make the effort of marking their territory worthwhile? That remains to be seen. Certainly nothing’s going to change in the short run, but I suspect that SEO types like Mr Duke above are protesting a bit too loudly at this point.

More nofollow thoughts

An extension of my post from this morning. As I read various objections to the nofollow tag, aside from the “It won’t actually instantly end all comment spamming” (which nobody…

An extension of my post from this morning. As I read various objections to the nofollow tag, aside from the “It won’t actually instantly end all comment spamming” (which nobody has claimed it would), the biggest cavil is, “It hurts commenters.”

This infliction of harm seems to be of two types.

  1. It treats all commenters as criminals.

    I suppose that’s true, although another way of looking at it is that it distinguishes between the original poster/site owner and others visiting (whether dear, bosom friends or evil spammers). I suspect that there will be some way of whitelisting or allowing registered users to comment without having nofollow in their links, but …

    But, even if so, so what? When we put moderation onto comments, we do the same tarring with a broad brush. When we put registration onto them, ditto. When we make folks type in Captchas and other such hoops, likewise. When we keep our MT password a secret, so that folks can only post comments, not actual blog entries, we’re treating others as untrusted.

    Deal with it.

  2. It robs commenters of something of value.

    The idea here is that people who make comments should get some sort of distinct reward, and the coin of the realm in this case is PageRank for their link targets.

    This is wrong, or beside the point, in so many ways.

    First off, if folks are commenting for PR, then screw ’em. Or, rather, I really don’t care whether they get that PR or not, so it’s not something I’m going to worry about.

    If they are conmenting to make a contribution to the discussion, then nothing has been lost by anyone. They’ve made their contribution, their content (and name and URL) are indexed, even if not PRed or spidered, and on display in front of God and everyone. All’s right with the world.

    I mean, already in MT (and this was widely applauded when it happens), the “Comment Author URL” field is redirected to keep spammers from using that field (and thus keep PR from accruing). If that’s not an evil thing, why is the nofollow tag (which effectively does the same thing) so bad?

    I may have a warped view of this, in that probably three quarters of my commenters don’t actually have a web site, and only a tiny fraction of my commenters include links. And of those links, only a small fraction as well are links back to their own pages. So this isn’t something that’s going to “hurt” my commenters.

    Trackback is slightly different, perhaps. Folks who trackback to articles here are, in theory, being similarly hurt because they didn’t get any PR for doing so. But, again, it’s hard to say that’s a distinct harm, unless that was your point in tracking back. The link is still there. I’m still likely to go out and look at the post in question. The poster has gotten something of value — my writing to refer to or be inspired by (hence the trackback). That their page should somehow be enrichened by their pointing to me seems a bit goofy.

    I’ll confess that I’ve a hankering for PageRank for myself. When I see that my front page is PR:5, I go, “Ooooooh, nifty.” I feel the same way about hit counts, or my rank in the TLB Ecosystem. But that’s such an indirect and passionless bit of whuffie that it’s insignificant next to folks actually caring to comment here, or trackback to my posts, or things like that. Those sorts of strokes aren’t dependent on PageRank, and so neither is my ego. Really.

    In other words, any “penalizing” I accrue by my comments on other pages not getting PageRank for my own blog is so trivial to my mind as to be non-existent. I find it hard, then, to empathize with the position that others find it intolerable.

Of course, none of this is either automatic nor unavoidable. If you’ve licked the comment spam problem on your site, implementing nofollow doesn’t really do anything for you, and thus can be avoided. But if stuff still gets through now and then, or you have a life beyond slapping down spammers as they hit, then I think it’s a fine long-term investment.

UPDATE: Anil Dash discusses how design decisions can have implications that could never be imagined — taking, as an example PageRank.

PageRank, when created, didn’t assume that content on a web page, especially links, would be generated by someone other than the publisher of that page. PageRank was not based on the assumption that the rankings would have monetary value. And PageRank is based on the assumption that site editors choose their content, particularly their links, based primarily on merit.

Because those assumptions no longer pertain in a blogging/wiki world, we end up with effects that were not predicted. How this applies to nofollow is discussed in further detail. A good read.

Hmmmm … what does nofollow actually do?

Here’s what Google says: From now on, when Google sees the attribute (rel=”nofollow”) on hyperlinks, those links won’t get any credit when we rank websites in our search results. Here’s…

Here’s what Google says:

From now on, when Google sees the attribute (rel=”nofollow”) on hyperlinks, those links won’t get any credit when we rank websites in our search results.

Here’s what MSN Search says:

Any link with this tag will indicate to a crawler it is not necessarily approved by this page and shouldn’t be followed nor contribute weight for ranking.

Here’s what Yahoo says … well, Yahoo doesn’t exactly say what their search bots will do with the link, just that it means that the link is not necessarily trusted by the site owner.

The 6A announcement says that the tag will :

… alert [Google’s] search spider that a particular link shouldn’t be factored into their PageRank calculations.

The MT nofollow plugin page says:

This initiative, with announced support from Google, Yahoo, MSN (and surely more to come), will direct search engines to ignore links with this attribute set for the purposes of spidering or increasing search engine relevance or ranking.

There’s two very different effects being described here.

  1. Search engines will not count links with the nofollow tag in page ranks.
  2. Search engines will not spider through links with the nofollow tag.

All the sites agree on #1, but effect #2 is not explicitly mentioned by Google (or by the 6A announcement). To my mind, #1 is what we’re particularly combatting here; #2 is a somewhat less desirable effect, though nothing that’s going to break the web, by any means. It’s just interesting that there’s no clear-cut description of how the search engines are actually implementing this.

Oh, and about that “untrusted” thing — wouldn’t it be an interesting variation on the nofollow plugin to have it not take effect on a certain class of commenters, e.g., a whitelist or Typekey-authenticated, or something like that? That might alleviate some of the “doom, doom, doomity-doom” chanting I’m hearing over this issue.

UPDATE: Jay Allen posts on it (and says, “search engines will ignore those links for the purposes of ranking (e.g. PageRank) and will not follow them when spidering a site”). But does he know? Or are different search engines treating it differently? As usual, though, his comments/trackbacks are the most interesting bits there (nofollow or not).

More on the Google nofollow tag

A bit of a backlash this morning on the announcement of the new rel=”nofollow” tag that Google et al. are going to be implementing. Most of the critiques are referenced…

A bit of a backlash this morning on the announcement of the new rel=”nofollow” tag that Google et al. are going to be implementing. Most of the critiques are referenced in this Register article.

While acknowledging that the new nofollow tag will not do anything — immediately — to stop comment spam, I think most of the criticisms are off-base in one way or another.

  1. The Internet is becoming balkanized, where people only accept content from people they know.

    This may come as a shock to some, but the Net is not a big wiki. Most web content is blocked against content from folks other than the creator. That blogs — and wikis — have the capacity to allow people other than a site owner/administrator to contribute is fairly amazing, and putting some restrictions on that is neither novel nor alarming.

    The “democratic nature of the web” doesn’t mean that everyone gets to post whatever they want on my site. It means that anyone can open their own site, and the web will “vote” on it by who links to it or visits it (and Google will index it regardless).

    I’ll say it again: comments are not the keys to blog content. Blog entries are. Of the blogs I visit, very few comments have links in them to go elsewhere — and, frankly, since those comments will still work, the damage to the “web” seems minimal.

    Now, if someone put the nofollow tag in their blog entries (which (a) nobody is proposing, and (b) the MT plugin doesn’t do), that would be a problem. But why would anyone actually do that, since the blog entry content is already protected? Again, this is not “invalidating” all links, just the Googling of those put into comments. Huge difference.

  2. The nofollow tag is “effectively declaring PageRank dead for weblogs.”

    Huh? I don’t know about most blogs, but for mine, there are rarely links in comments (except from spammers) and rarely is it key to the actual post content. Comments in a blog are not really the same as discussions on a discussion board, in a variety of ways. If links coming out of comments are no longer considered in PageRanks or somehow indexed in Google, I don’t think that’s a huge problem.

    And if there’s a really key link that I think, from a comment, should be highlighted and PageRanked and all that, I can (as the original post owner) put it up in the actual post itself as an “UPDATE.” (Conversely, if I want to reference a site that I think is particularly despicable, I can now do so as a link, manually, without worrying that I’m boosting their Google ranking. That’s not necessarily a bad thing.)

    Now, what this does mean is that if I’ve written about subject X, and I comment on someone’s blog (that’s implemented this solution) and say, “I’ve written in more detail about this at [link back to my blog entry],” that cross-link won’t get indexed, my blog page won’t get a PageRank boost, and a search in Google for pages that mention my pages won’t see it. Boo-hoo. Folks can still click on the link. And since I wasn’t sobbing that such a comment didn’t generate a Trackback (in MT, at least), I don’t see why I should be sobbing that it doesn’t boost my PageRank — unless PageRank is what I’m looking for.

  3. This does nothing to stop comment spam, but other things like Captcha does.

    There are two ways to disincent behavior. One is to make the behavior more difficult or painful or costly to perform, and the other is to make the payoff for the behavior less attractive. Captchas and blacklists and the like are part of the former, creating armor and fortifications against folks being able to willy-nilly post content. The nofollow tag takes the latter approach, making the reward for actually getting comment spam posted that much less. The two approaches are complimentary, not swappable.

    I’ve toyed with using Captchas here before, but have refrained for two reasons. The first (and, admittedly, minor) one is that Captchas are unfriendly to those with visual handicaps. The second is that, for determined comment spammers, there are ways to get around them, to essentially recruit humans to solve them for the spammers (either through pittance payments to third-worlders or by tying them into pr0n sites where someone resolves an intercepted Captcha to get in to see something, which then lets the site owner get in to where the Captcha was originally formed). I don’t know how common this bypassing is, but it’s at least conceivably possible, and as long as there is a reward for going to the effort, the effort will be gone to. Hence the long-term potential for the nofollow tag.

  4. Spammers will just go to blogs that aren’t using the nofollow tag.

    Ultimately, yes, though it assumes that spammers are really looking at the sites they’re going to (and my experience is that they don’t, much). But if they do, that’s still a victory for me, because it means they’ll leave my site alone.

    The same, though, can be said for any defense, whether it’s blacklisting or moderation or ID verification or whatever. Burglars will hit the obvious targets on a street. Virus writers depend on the folks who have no AV on their system and never download security patches. That’s a separate problem (how to encourage updates, what to do about abandoned sites), but it doesn’t invalidate what the nofollow tag can do in this case.

The Register article, aside from taking a snarky attitude toward blogs in general, is missing the point. This approach seems to me to be a good, long-term way to disincent comment spamming, with minimal effect on the blogs or the Net itself. I’m not sure where the problem is with that.

IT DOESN’T WORK ANY MORE! DO YOU FINALLY GET IT!?

(The above is a message to comment spammers.) Comment spammers do their evil and fœtid thing in order garner high Google pageranks for their sites. MT long ago set up…

(The above is a message to comment spammers.)

Comment spammers do their evil and fœtid thing in order garner high Google pageranks for their sites.

MT long ago set up the URL field in comments to automatically be set up as redirects (so that they couldn’t be used for pagerank purposes), but comment spammers have long turned to posting their nasssssty links inside of the comments themselves.

So 6A has created the “nofollow” plugin. Google, MSN Search, and Yahoo have agreed that their search bots/spiders will no longer record links with with the rel=”nofollow” attribute. The plug-in, in turn (as you have probably figured out) inserts that particular tag into all links in comments.

The plug-in has been tested in MT 3.x and 2.661.

TypePad users will have this automatically happen. LiveJournal plans to implement this for folks that aren’t “friends” of the poster.

Very good. I’m not a fan of ad hoc extensions of standard syntax, but this seems a relatively harmless and acceptable cooperative action to — well, if not stop comment spammers, at least discourage them. After all, once it’s in place, comment spam (to garner pagerank) is useless.

IT DOESN’T WORK ANY MORE, ASSHOLES. GO AWAY. NOW. JUST. GO. AWAY.

I heartily recommend folks adopt it. I’m going to.

Spam by proxy

At the suggestion of a couple of sites, including 6A, I installed over the weekend Brad Choate’s MT-DSBL plug-in, which attempts to use open proxy information from DSBL to identify…

At the suggestion of a couple of sites, including 6A, I installed over the weekend Brad Choate’s MT-DSBL plug-in, which attempts to use open proxy information from DSBL to identify potential comment spammers.

So far, though, the only folks blocked were Randy and Mary, two people I’m pretty certain are not spammers (and who, presumably, are using respectable ISPs). Their comments dropped into moderation (and were posted this morning), but unlike MTBL, I had to actually view the Comments queue to spot them.

We’ll see how it works over the next week or so, but my inclination is at this point to drop MT-DSBL.

Spam by any other name …

So, a somewhat disturbing evolution in the War on Comment Spam — the stealth URL. And it shows why blacklists will only ever be of limited use as time goes…

So, a somewhat disturbing evolution in the War on Comment Spam — the stealth URL. And it shows why blacklists will only ever be of limited use as time goes on (as Jay Allen himself is the first to admit).

I’ve seen an increasing amount of comment spam coming in pointing at domains that combinations of names and/or words. “Candicesmith.org” or “FredCorp.com.” Those are URLs that cannot be detected by any blacklist. And if the post text has either innocuous words (“girls!”) or else something munged with HTML entities that reads legibly to the eye but not to the computer, there’s no way to blacklist against it.

There was originally a sense that you could use URL strings to detect spam, because comment spammers’ customers would want you go see that their URL was for [illicit product] and click through on it. But if readers get the metadata they need from the comment text, and if the spammers can say, “Hey, look, I’ve generated 52,000 links and a high Google pagerank for FredCorp.com (which probably redirects to MyWhatNaughtyVixins.com),” then the spammers and their customers get what they want. That makes the trivial cost of a domain acceptable (and lets the spammers start using more legitimate domain salesfolk).

Feh.

Moderating everything would be an option, but that restricts a lot of the fun we have here. Right now, through MT-Blacklist, I force to moderation for comments on posts over a certain age that haven’t had comments on them in the last defined interval. During the most recent attack last night and into this morning, about 100 comments got put into the system, but only one got accepted because it was posted to a recently commented-upon post (and how soon before that info starts becoming cracked by the spammers scripts?). It just takes a while to clean out the garbage, which is moderately satisfying (“And stay out!”) but irksome at the same time.

I could require authentication (e.g., TypeKey). I’m not there yet, though. I really don’t want to require people to sign in first. But I’m getting closer.

It is a puzzlement.

UPDATE: And, in validation of the “broken windows” theory (broken windows in a neighborhood provokes more broken windows; uncleaned graffiti prompts more graffiti), some proof that uncleaned comment spam breeds more comment spam.

(via Jay)

What about Bob?

Some fellow self-named “Bob” has been having a merry time spamming both my and Doyce’s wikis over the last couple of days. If there was one upside to the recent…

Some fellow self-named “Bob” has been having a merry time spamming both my and Doyce’s wikis over the last couple of days. If there was one upside to the recent DOS attacks on HostingMatters, it was that it inconvenienced Bob, too.

I probably need to just go in and edit-protect most of the Wiki stuff I have out there anyway, since (with a couple of exceptions) it’s not so much intended for multiple user access. In the meantime, I’ve made use of the very convenient “Restore” functions in PmWiki, as well as the change tracking and RSS feeds I get.

Bob is scum, like most of his ilk. Here’s hoping that something appropriately dreadful happens to him — as a learning experience, of course.

You got to know when to hold ’em

Best MTBlacklist URL Pattern ever: \bpoker\b Which has blocked 88,200 spams. Yes, that’s an accurate number. Although … texas.*hold.*em … has blocked 88,050. Crikey. Most over the last few days….

Best MTBlacklist URL Pattern ever:

\bpoker\b

Which has blocked 88,200 spams. Yes, that’s an accurate number. Although …

texas.*hold.*em

… has blocked 88,050.

Crikey. Most over the last few days. And all without my even seeing them. I wouldn’t have even known, had I not looked in the list in reference to some other odd trackback that got through.

Six Apart has issued a nice document on fighting comment spam, entitled, appropriately enough, The Six Apart Guide for Fighting Comment Spam (PDF). Worth a read.

Criminals are a cowardly, superstitious, and stupid lot

Dear Valued Customer, – Our new security system will help you to avoid frequently fraud transactions and to keep your deposited funds in safety. – Due to technical update we…

Dear Valued Customer,

– Our new security system will help you to avoid frequently fraud transactions and to keep your deposited funds in safety.

– Due to technical update we recommend you to reactivate your account.

Anyone who gets taken in by this plaintext e-mail message probably deserves to get their credit card information stolen. Yeesh.

Feel like sitting on the front porch with a shotgun

Some reprobate, signed in as “dfg,” has been spamming my wiki over the past few days. He’s been increasingly subtle about it, though the Page Histories still show it; they…

Some reprobate, signed in as “dfg,” has been spamming my wiki over the past few days. He’s been increasingly subtle about it, though the Page Histories still show it; they also make it easy to correct, but I hate having to be vigilant about watching it.

If it keeps up, I’ll have to password protect the whole thing, which I’d really rather not do. But I’m not going to have folks who combine the worst of both taggers and phone solicitors mess up my personal space, dammit.

Shields are holding, Captain!

While a bit of comment spam got through whilst I was away, much much more got blocked, and the clean-up of the evaders plus those thrown into moderation took only…

While a bit of comment spam got through whilst I was away, much much more got blocked, and the clean-up of the evaders plus those thrown into moderation took only about twenty minutes. Huzzah.

This looks like a job for Dave Hill, International Man of Mystery!

How many countries can you reference in a few short paragraphs? Dear sir/madam, This mail will definitely be coming to you as a surprise, but i must crave your indulgence…

How many countries can you reference in a few short paragraphs?

Dear sir/madam,

This mail will definitely be coming to you as a surprise, but i must crave your indulgence to introduce myself to you.

I am Miss Marah sadija, former mistress to the son (Qusay) of the Iraqi former leader, Saddam Hussein. I am an Ethiopian, by birth and i am presently in a refugee camp in Zimbabwe, where the living conditions are unbearable. I do not wish to take your time with a lenghty mail, but i have to put this proposal to you so that you can assist me.

While i was still in contact with Qusay,he made a deposit in my name to a security firm in Spain, which has an affiliate branch in Amsterdam. This deposit was made in my name and the secret code and necessary documents are presently in the possession of an attorney, presently in London ….

Just follow the money …