One more thing I wanted to find out about. How do you handle email signatures? When someone comments on a task in BaseCamp (via email) the entire email is posted to the thread, including their signature and whatever little images they included (photograph, or Facebook/Twitter icons). Is there anything you can do about that? Gmail seems to be pretty good at detecting the boilerplate part of a message -- possibly only after having seen one message from the user. This would be an important thing to nail.
Edit: What if you want to lock a page down so that only you or a select few may email updates? I would probably want that for at least one of the pages. Now that I'm thinking about it, the lack of registration is possibly due to how hard it would be to authenticate a user via easily-spoofed email. You might be able to come up with a sort of "secret key" that you add anywhere in the email but I could see that not working out for your average user.
As for handling spam, yes it is a challenge but something we plan on doing to prevent spam is sending automatic authentication links to accounts we believe are posting a high volume in a short period of time. The authentication link will lead them back to a page that requires them to fill out a different captcha for each link.
Finally with regards to signatures, there is definitely OER software that exists that we can test out handling signatures and images inside the email itself.
The authentication link is a good idea. They can still post non-automated messages (and automated messages if they find the right lib for breaking captchas) but at the very least it will give you a way to keep a close eye on suspicious activity. Someone starts triggering the captcha? Take a look at what they do.