Whitelist, Blacklist, Greylist

Having recently switched from bblog (I know, I know) to Wordpress, I have so many new options of spam fighting now. I’m curious if a bot busting idea that other sites use is active in comment spam busting.

Was the comment page loaded in before the comment was posted? How long? I know this wouldn’t help trackback spam but it would take a big bite out of the 40,000 comments and trackback spam I had on my old blog.

Yes, I’m looking into the timing of comment spam and the possibility of a plug in to WP.

Interesting article proposing a whitelist approach to anti-virus. He makes an excellent point…

http://www.it-director.com/blogs/Robin_Bloor/2007/3/avid_why_it_s_over_for_the_antivir_.html

The real problem is mixed case captcha. Many letters look the same, and since captcha often changes sizes, it’s literally impossible to tell the different cases of the lettes. At the very Least, implementors should make captcha case-insensitive.

The other maddening thing is you are usually cut off after three or four tries and have to wait a day. This is insane. All they need is a timer. No robot is going to take five minutes doing captcha-errors. The slow timing as a victim struggles with case-sensitive captcha guarantees it’s a human. A pissed-off human.