<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom"><generator uri="http://www.habariproject.org/" version="0.10-alpha">Habari</generator><id>tag:mattread.com,2020-02-06:openid/8570b76d965d9aabc07ffb82b7ac6c3a35ed2dea</id><title>Matt Read, Weblog</title><subtitle>It says little, does less, means  nothing.</subtitle><updated>2008-12-12T10:21:37-05:00</updated><link rel="alternate" href="https://mattread.com/tag/openid"/><link rel="self" href="https://mattread.com/tag/openid/atom"/><entry><title>A Bold Move To OpenID</title><link rel="alternate" href="https://mattread.com/a-bold-move-to-openid"/><link rel="edit" href="https://mattread.com/a-bold-move-to-openid/atom"/><author><name>Matt Read</name><uri>https://mattread.com</uri></author><id>tag:mattread.com,2008:a-bold-move-to-openid/1229095297</id><updated>2008-12-12T10:21:37-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2014-10-08T18:55:04-04:00</app:edited><published>2008-12-12T10:24:58-05:00</published><category term="comments"/><category term="openid"/><category term="spam"/><category term="identity"/><content type="html">&lt;p&gt;After deleting thousands of spam comments every week, I got fed up. I went looking for a way to eliminate spam all together. There are many different approaches that work at completely destroying spam bots A Honey Pot, &lt;a href="http://svn.habariproject.org/habari-extras/plugins/spamhoneypot/"&gt;a Habari plugin&lt;/a&gt; by &lt;a href="http://seancoates.com/"&gt;Sean Coates&lt;/a&gt;, that adds a CSS hidden field that only bots would fill in; encoding the &amp;#8220;action&amp;#8221; URL, and input elements names and ids of the submitting form, a technique used by &lt;a href="http://gsnedders.com"&gt;Prof. Sneddy&lt;/a&gt;, killing all spam bots which don&amp;#8217;t use an HTML parser (which is all of them). There are others, but those are two that I find work reliably.&lt;/p&gt;

&lt;p&gt;&lt;img alt="OpenID Logo" src="//mattread.com/user/files/openid.png" class="right"&gt;&lt;/p&gt;

&lt;p&gt;The above mentioned methods, however, do not provide any way to authenticate the identity of the submitting comment author. In comes &lt;a href="http://openid.net/"&gt;OpenID&lt;/a&gt;. Using &lt;a href="http://openid.net/"&gt;OpenID&lt;/a&gt; to authenticate that the commenter is who they say they are, allows us to ensure that only valid comments are submitted. Since I haven&amp;#8217;t seen a spam bot with an &lt;a href="http://openid.net/"&gt;OpenID&lt;/a&gt;, this will absolutely stop them in their tracks.&lt;/p&gt;

&lt;p&gt;&lt;a href="http://openid.net/"&gt;OpenID&lt;/a&gt; also allows to use heuristics to determine which &lt;a href="http://openid.net/"&gt;OpenIDs&lt;/a&gt; can be trusted, and which can be blacklisted. Since every commenter has a unique authenticated &lt;a href="http://openid.net/"&gt;OpenID&lt;/a&gt;, we can reliably trust repeat commenters and push their comments through the moderation queue; at the same time, not trust blacklisted &lt;a href="http://openid.net/"&gt;OpenIDs&lt;/a&gt;, deleting them immediately, without needing any human interaction to &lt;em&gt;reliably&lt;/em&gt; do so.&lt;/p&gt;

&lt;p&gt;I&amp;#8217;ve decide to jump head first into the deep end, and only allow comments to be submitted using an OpenID Identifier. This means, that if you want submit a comment on my site, you &lt;em&gt;must&lt;/em&gt; have an &lt;a href="http://openid.net/"&gt;OpenID&lt;/a&gt;. There are many people who do not have an &lt;a href="http://openid.net/"&gt;OpenID&lt;/a&gt; yet, but for your protection, and mine, I would highly recommend you go out and get one now.&lt;/p&gt;

&lt;p&gt;I use &lt;a href="https://pip.verisignlabs.com/"&gt;Verisign&amp;#8217;s &lt;abbr title="Personal Identity Portal"&gt;PIP&lt;/abbr&gt;&lt;/a&gt; service for my OpenID provider. The service is still in &amp;#8220;beta&amp;#8221; (whatever that means nowadays) but I would highly recommend it. They even provide phishing detection, and &amp;#8220;Strong Authentication&amp;#8221; methods, including Browser Certificates, and their &lt;a href="https://idprotect.verisign.com/learnmore.v"&gt;VIP Credetial&lt;/a&gt;. Go sign up!&lt;/p&gt;
</content></entry></feed>
