Archives

April 2004 (7)
March 2004 (12)
February 2004 (12)
January 2004 (22)
December 2003 (19)
November 2003 (16)
October 2003 (26)
September 2003 (18)
August 2003 (38)
July 2003 (80)
June 2003 (13)
May 2003 (24)
April 2003 (76)
March 2003 (75)
February 2003 (51)
January 2003 (73)

Category

Family (5)
FYI (18)
Games (2)
Geek (88)
Geographic (3)
Hacks (13)
Home (15)
Humor (54)
Ideas (20)
Ideaspace (15)
Local (15)
Metadata (10)
Microsoft (2)
MovableType (5)
Nitwits (66)
PKI (2)
Politics (22)
Quotes (3)
RDF (15)
RSS (4)
Security (3)
Semantic Web (13)
Site Info (13)
Social Networks (1)
Spam (9)
Sysadmin (1)
Tips (2)
Tivo (2)
TMFTOTHD (1)
To Do (1)
Unlisted (1)
Web (3)
Windows (1)

Local

« MetroBlogs »
DC metroblogs
beltway bloggers

Links


Assorted bits

Blogroll Me!
GeoURL
Listed on BlogShares




March 27, 2003

Toward secure comments

Trackbacks, once your get your apache server chroot properly configured, are a cool thing. You create a post and you paste the other site's trackback URL into the form and MT does the rest. The rest being it takes that URL, contacts that site and sends it the relevant bits from your site. All done for you.

Now, here's the trouble, how does the receiving site know whether or not it wants trackbacks from you?

We've seen comment spam and Winer's certainly had this past bouts of 'how dare you call me on facts in my own discussion group' woes. While getting feedback is always a good thing sometimes trouble develops. So how do we setup comment systems like this that allow the recipient of the comments a little bit of control over incoming messages?

Using per-site registrations is one way. This, frankly, sucks. It requires the poster to have an account on your site AND to remember the unique password for it.

If you sign up for a site and use that same password used elsewhere, guess what happens when one of the sites get's hacked? Right, they can then attack your accounts everywhere you used the password.
An alterantive is to use a third party of some kind that you can both mutually trust. You get a key from me and send a message to me signed with both yours and my keys. Your key can be verified from the third party. I get the message, check the key against the third party and ones I already know and verify that it was signed to me.

What would it take to make this painless? Or, if not painless, at least reasonably automatic. One step would be to put your public key on your web pages such that a tool like TrackBack can find it. The tool could then post the message encrypted against that key.

Ideas
Perma  | Comments (0) | TrackBack (0) | 12:55 PM  | xml
Comments
Post a comment






* if you do not leave a valid e-mail or URL your comment may be deleted *







Navigation

Recent Entries

America and Europe: Vive la différence?
Server changes afoot
Diet behavior mod
Googling for sensitive info
Outlook 2003 and IMAP, a marriage made in Hell
Bike to Work Day, May 7th
Speakeasy rocks
Zippo USB?
When geographic data is nowhere 'near' correct
Local campaign contributions

User comments
Trackbacks

Contact

send me an e-mail E-mail
chat with me using MS messenger MSN Messenger
chat with me via AIM America Online
chat with me on ICQ ICQ
chat with me on Yahoo! Yahoo
Add my vCard to your electronic addressbook vCard
Friend of a Friend FoaF

Syndication

XML  RDF  CDF

Comments

XFML

Extra Stuff

foaf
vCard
pgp info
Linked In
Powered by
Movable Type 2.64