Show HN: Comntr – a widget that adds comments to your page
comntr.github.io
comntr.github.io
https://github.com/comntr/http-server/blob/master/src/handle...
Some time ago i did a scroing and visualization of reddit threads, maybe you find it useful, see https://migor.org/reddit/#/discussion/top?url=https:%2F%2Fww...
comntr.github.io#http://foobar.com/
See e.g. at https://mro.name/blog/2009/08/nsdateformatter-http-header/
> Commento is a proud recipient of the Mozilla Open Source Support award. The $19,200 grant was given in recognition of Commento's contributions to make the internet more privacy-friendly.
That said, it uses akismet for spam control, which I'm not sure how trustworthy it is... But definitely better than nothing!
> Site Comments: When a visitor leaves a comment on a Site, we collect that comment, and other information that the visitor provides along with the comment, such as the visitor’s name and email address.
> Technical Data from a Visitor’s Computer and Etcetera: We collect the information that web browsers, mobile devices, and servers typically make available about visitors to a Site, such as the IP address, browser type, unique device identifiers, language preference, referring site, the date and time of access, operating system, and mobile network information.
> We may determine the approximate location of a visitor’s device from the IP address. We collect and use this information to, for example, tally for our Users how many people visit their Sites from certain geographic regions. If you’d like, you can read more about our Site Stats feature for WordPress.com sites and Jetpack sites.
> Akismet Commenter Information: We collect information about visitors who comment on Sites that use our Akismet anti-spam service. The information we collect depends on how the User sets up Akismet for the Site, but typically includes the commenter’s IP address, user agent, referrer, and Site URL (along with other information directly provided by the commenter such as their name, username, email address…oh, and the comment itself, of course).
> A cookie is a string of information that a Site stores on a visitor’s computer, and that the visitor’s browser provides to the Site each time the visitor returns. Pixel tags (also called web beacons) are small blocks of code placed on Sites. Automattic uses cookies and other technologies like pixel tags to help identify and track visitors and Site usage, and to deliver targeted ads
> We also collect any other information that our Users provide to us about visitors to their Sites. For example, a User may upload a directory or other information about Site visitors and customers to the “backend” administrative platform for managing the Site. How We Use Visitor Information
> We use information about Site visitors in order to provide our Services to our Users and their Sites. Our users may use our Services to, for example, create and manage their Site, sell products and services on their Site, flag and fight comments from spammers, and collect information through polls, quizzes and other surveys.
> We may also use and share information that has been aggregated or reasonably de-identified, so that the information could not reasonably be used to identify any individual. For instance, we may publish aggregate statistics about the use of our services.
Then there's Gravatar, which is another method of user tracking and I'm sure there's a slew of other ways.
For high traffic websites, simply the task to review new comments by new users, can be too much work. So needs to be combined with something automatic like Akismet. Based on what I've heard.
Your initial "puzzle" can be solved with 8 characters of JS: eval("23+47").
Your SVG picture can be solved using off-the-shelf OCR like Tesseract.js.
Even very challenging reCAPTCHA reading tests are mostly solvable by spammers.
You'd be better of using something with thousands of expert person-hours behind it, like reCAPTCHA v2.
I used a bunch of one-word-answer questions for over a decade now for sucessful spam prevention — trivial for a determined attacker with the time and resources to circumvent (and similarily trivial for me to replace with something else).
This also means for a decade I didn’t ship my user data to google.
Unless you are a really juicy target fending off the bots is enough.
The puzzle will be sent as an SVG, obviously.
Em.. "off-the-shelf OCR" sounds neat, but anyone who knows such words isn't an average spammer. The goal of basic SVG puzzles is to block 99% of the spammers who just type dumb comments on keyboards. The rest 1% can be taken care of by human mods.
TBH, I don't like the reCAPTCHA-like solutions. They are just annoying from my personal experience and if they rely on any 3rd party service, I'll give them a hard pass for this reason alone. My approach is to use trivial SVG-style captchas with adjustable complexity, e.g. instead of asking "23+34", we can ask "log(32)/log(2)" and effectively filter out everyone except people familiar with math, or "md5(2615), first 7 hex digits" and let in only people familiar with cryptography. Forcing users to detect birds and crosswalks will just make them upset, IMHO.
It's an XML document that should be easier to figure out than a raster image format such as jpg or png.
Granted all you need to do is render it to a canvas but that’s an extra step on top of everything you need for a raster image, I’m not sure it’s easier.
I work on a site with 10 million monthly pageviews and spammers register on a form that has recaptcha and email verification... and we tried hidden input fields and other tricks, but each day we have consistently had 5 new spam accounts. With SVG they can just take a screenshot of what a user sees and send that to OCR. Complex math will turn away as many legitimate users as spammers.
The only real way to stop spam is to use a 3rd party API to detect it, or use something like a karma system that builds up over time. I think we're at the point where simple solutions won't work well unless you have a small site.
This will make it impossible for blind people to post a comment. There are ways around it, but one has to be aware of this issue.
A lightweight comments widget built on GitHub issues.
Themoreyouknow.jpg