Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Wednesday, July 15, 2009

Blog under spamming attack – end of anonymous comments?

I just noticed that my blog on “Research on Identity Management”, hosted by the HP portal, is under “comment spamming” attack.

This is not a major issue as the current blog platform’s security controls just filter these undesired comments.

However, in my view, this shows how the capability of having anonymous posting of comments can be easily abused.

I believe this capability will be increasingly disabled in most blog sites. The same could happen for “authenticated” comments, as most of the time this just requires a user setting an account with a fake profile, hence enabling spammers to post again their comments.

Switching-off the capability of posting comments or introducing further controls will make the blog experience harder and harder …

--- Posted by Marco Casassa Mont (here and here) ---


--- NOTE: my original HP blog can be found here ---

No comments: