Many people began experiencing comment spam, and pre-Akismet there were many solutions from a tarpit to moderation word lists. Curiously though I got no spam. Zero. Eventually, after seeing the size of the problem hitting other sites I checked the access logs.
My blog was at http://example.com/T2/
The logs showed I was being battered by spam, but they were hitting http://example.com/t2
That uppercase letter had been inadvertently saving me for months. Of course the spammers wised up but I found it amusing at the time.
The reality in 2024, alas, is that spambots long ago learnt to defeat these approaches.
After trying several clever techniques like the one in the article, we eventually and reluctantly added a CAPTCHA.
For a CAPTCHA, we are using Cloudflare’s Turnstile.
According the the article the spinner is a hidden field that consists of an MD5 hash of The timestamp, The client’s IP address, The entry id of the blog entry being commented on, and A secret. This makes me wonder how a hash of the timestamp is verified? Does it generate MD5 hashes of the last hour or so of timestamps and authorise the post when one of them matches? How else would it know the exact timestamp used to generate the form submission?
- login page opened
- there was a seed value embedded in the form
- the page also loaded a Javascript implementation of MD5
- use enters their password
- the page hashes the seed and the password
- the POST only sends the hashed value above
Everything is https these days so you don't really see this anymore but I've always liked this piece of internet history.