The comment section of this site is increasingly being attacked by spambots. Vying for your attention, these messages mainly offer links to videos – from latest releases to more scantily clad escapades. The messages I have the greatest trouble rejecting, however, are the ones that say something nice … and just happen to link to some scam site offering viagra, discount software or such. To be honest, I have thought about letting these comments pass, with a quick edit to remove the offending URL.
Almost all of these messages come from eastern Europe. Many are in Russian. The spambots mainly seem to attack a small number of posts with a couple of messages each day. I have played around with some of these posts, and the spambots still try to comment on posts after they have been removed – so they must be automated in some way.
To date I have been using Peter’s Custom Anti-Spam, this is why you had to type in some distorted word in when commenting. While it initially worked well, in the past couple of months it has been letting far too much through. I tried changing the captcha words list, but this was to no avail. Further I had complaints that this raised the barrier to posting legitimate comments to far.
Next I turned on Akismet. I should have done this from the beginning, it has stopped all of the spam and let through all of the real comments. But I still wasn’t happy – the spambots were still sending messages for me to moderate.
Next I thought it would be better if I only allowed comments from authenticated users. Given how much I hate passwords and that people complained about the captcha words, I wanted an OAuth solution, like that used by TripIt.
I found and installed Janrain, which allows people to register with a couple of by authenticating against Google, Facebook, Yahoo or WordPress before commenting. This also allowed me to get rid of the captcha word.
In the hours since setting this up I haven’t had any of the expected spam – but only time will tell how good this solution is. I’ll keep you posted.
