I have comments, but no spam in my comments. Here’s why.
tbray.org
tbray.org
But honestly, I hate blog comments. Being able to read a number from an image doesn't mean that what your writing is worthy of being published. (I keep them enabled because I like the fact that people are occasionally so upset with my analysis of Java's type system that they want me to "die in a fire". Really? What exactly would that solve?)
With the exception of a few places like HN, the best comments are treated about the same as bad comments. The absence of incentives leads to the absence of quality.
The other issue is related in the sense that if there was a good mechanism for aggregating comments across sites it would almost certainly serve to recognize and reward the best comments. Solve the fragmentation problem, and you get resolution on the first one for free.
This prevents pointless comments and flamewars--of course, it also means I probably won't let you flame me baselessly in my blog comments, but there's no free speech on a private website anyways.
I like this better because there's a much smaller chance of a flamewar happening, and the responses will generally be well thought out.
comments flagged as spam by defensio require an email address to go into the database (if it wasn't spam it doesn't require an address and will just post to the site right away). the user is then emailed a link that they have to click on to make their comment show up, which then notifies defensio it was a false positive.
eventually i grew tired of the email bouncebacks from the spam submissions, so i started caching the ips that submitted the spam and automatically blocked access to the entire site from the ip after a number of spammy comments queued up. the comment spammers just flood the site with spam very quickly, so their spam count exceeds that quota and they are forever blocked just as quickly.
I'm guessing this is due to its... non-standard construction. It's pure XML plus an XSLT that transforms it into HTML on the client side.
A more sensible approach might be to use XSLT to transform just the FORM stuff on a "real" blog system, but I haven't tried that. If the bots are using real browsers when trawling the net and not just some regexps it'll provide no protection.
If you're curious it's over at http://eiman.tv/blog/
What do you do for IE? :)
It hasn't been on my list of priorities. Might work in IE7 or IE8, but I haven't tried it.
For every target that is even slightly hardened there are half a million soft targets out there. Better to go after those, the ROI is higher.
If you had lots of visitors it would be worth their time to figure out a way to get in there. Think of spammers as a measure of success, if you are anywhere near successful the spammers will find you, count on it.
XML is a simplified subset of SGML, which as I stated was an invention of IBM.
Moot these days I suppose. A horrendous 'technology' that has seen its day pass and be replaced by considerably improved markup languages.
I wanted to avoid image captchas, which I consider to be a usability barrier. Instead, I implemented a really simple, three-pass filtering system for comments by anonymous visitors (registered visitors can log in and bypass the spam filtering system entirely). It included the following three steps:
1. Ask a very simple grade-school math question using plain text.
2. Check comment text against a list of 56 common spam words. (This is actually rather crude: anonymous comments including, say, "socialism" trip the filter for "cialis").
3. Include a hidden form field that is supposed to remain blank.
That was in June 2008. Since then, not one spam comment has gotten past the filters.
I should note that my site, like Tim Bray's, uses a CMS I developed from scratch (starting about five years ago), so it's likewise not subject to the exploits that target Wordpress or Drupal or the other popular CMSes.
I'm surprised that this solution has not been adopted yet by the most popular blogging softwares.