<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Bad Behavior Spam Blocker Part 1</title>
	<atom:link href="http://blog.ericlamb.net/2009/05/the-bad-behavior-spam-blocker-part-1/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ericlamb.net/2009/05/the-bad-behavior-spam-blocker-part-1/</link>
	<description>Thoughts on programming, people and life</description>
	<lastBuildDate>Sat, 04 Feb 2012 09:01:37 -0800</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: ip hiding software</title>
		<link>http://blog.ericlamb.net/2009/05/the-bad-behavior-spam-blocker-part-1/comment-page-1/#comment-8651</link>
		<dc:creator>ip hiding software</dc:creator>
		<pubDate>Fri, 27 Aug 2010 15:01:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ericlamb.net/?p=1504#comment-8651</guid>
		<description>No.  The Blackjack runs Windows Mobile 5 Smartphone edition or Windows Mobile 6 Standard.  Both of these are very limited versions of the Windows Mobile operating system.  I doubt that Cisco is even inclined to make a VPN client for these versions.  Windows Mobile 5 Pocket PC and Windows Mobile 6 Professional are much more likely candidates for the VPN client.  Unfortunately, even if Cisco makes a VPN client for these operating systems the Blackjack cannot run them. Sorry.</description>
		<content:encoded><![CDATA[<p>No.  The Blackjack runs Windows Mobile 5 Smartphone edition or Windows Mobile 6 Standard.  Both of these are very limited versions of the Windows Mobile operating system.  I doubt that Cisco is even inclined to make a VPN client for these versions.  Windows Mobile 5 Pocket PC and Windows Mobile 6 Professional are much more likely candidates for the VPN client.  Unfortunately, even if Cisco makes a VPN client for these operating systems the Blackjack cannot run them. Sorry.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lialleync</title>
		<link>http://blog.ericlamb.net/2009/05/the-bad-behavior-spam-blocker-part-1/comment-page-1/#comment-1283</link>
		<dc:creator>lialleync</dc:creator>
		<pubDate>Sat, 10 Oct 2009 21:44:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ericlamb.net/?p=1504#comment-1283</guid>
		<description>Hey very nice blog!! Man .. Beautiful .. Amazing .. I will bookmark your blog and take the feeds also...</description>
		<content:encoded><![CDATA[<p>Hey very nice blog!! Man .. Beautiful .. Amazing .. I will bookmark your blog and take the feeds also&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eldris</title>
		<link>http://blog.ericlamb.net/2009/05/the-bad-behavior-spam-blocker-part-1/comment-page-1/#comment-948</link>
		<dc:creator>eldris</dc:creator>
		<pubDate>Sat, 09 May 2009 00:06:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ericlamb.net/?p=1504#comment-948</guid>
		<description>Thanks for providing even more of your insight on it :D I&#039;ll definitely keep it in mind for if ever my blog gets more popular, either with spammers or legit readers. This could probably be a useful tool for a lot of bloggers.</description>
		<content:encoded><![CDATA[<p>Thanks for providing even more of your insight on it <img src='http://blog.ericlamb.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  I&#8217;ll definitely keep it in mind for if ever my blog gets more popular, either with spammers or legit readers. This could probably be a useful tool for a lot of bloggers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Lamb</title>
		<link>http://blog.ericlamb.net/2009/05/the-bad-behavior-spam-blocker-part-1/comment-page-1/#comment-946</link>
		<dc:creator>Eric Lamb</dc:creator>
		<pubDate>Fri, 08 May 2009 19:31:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ericlamb.net/?p=1504#comment-946</guid>
		<description>Eldris,

I agree, Bad Behavior isn&#039;t perfect but &lt;a href=&quot;http://blog.stackoverflow.com/2009/02/new-question-answer-rate-limits/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;nothing single technology really is&lt;/a&gt;. I still get comments through Akismet and Bad Behavior and legitimate comments get false positived (yeah, positived could be a word) by Akismet.

One thing I like about Bad Behavior is that it doesn&#039;t actually stop bots from commenting directly; it stops bots from even seeing your blog (so they don&#039;t even know about the comment form). To protect against false positives, a user being flagged as a bot, there&#039;s a confirmation screen just in case. (I admit the confirmation scenario is pretty weak; but until I can come up with something more clever it&#039;ll have to do.)

Before I installed the Bad Behavior plugin into my blog, I was getting around 30 spam comments a day. Almost half of my reported traffic was spam! Everyday I would log into my admin and have to scan every comment to see what was real and what wasn&#039;t. 

Even though this process only took a few minutes it was still disruptive to my day. Plus, you know, $Eric = &#039;Lazy&#039; so I try to keep my mental load low. This was just too much to do every, single, day.

I had used Bad Behavior on a client site once, and was pretty happy with it&#039;s results, so I installed the Bad Behavior WordPress plugin. My comment spam dropped to about 2 a week. I&#039;m not exaggerating.

As to the IP issue; also not ideal but it&#039;s not the sole criteria to block something. Bad Behavior also looks at the headers and stuff (stuff &lt;em&gt;is the&lt;/em&gt; technical term) which are also pretty easy to manipulate. 

You just have to keep in mind that programmers who work for spammers are usually the bottom of the barrel. Seriously, the good programmers get better jobs so the majority of the spammers are pretty bad and don&#039;t implement the advanced techniques to hide their tracks.</description>
		<content:encoded><![CDATA[<p>Eldris,</p>
<p>I agree, Bad Behavior isn&#8217;t perfect but <a href="http://blog.stackoverflow.com/2009/02/new-question-answer-rate-limits/" onclick="return TrackClick('http%3A%2F%2Fblog.stackoverflow.com%2F2009%2F02%2Fnew-question-answer-rate-limits%2F','nothing+single+technology+really+is')" target="_blank" rel="nofollow">nothing single technology really is</a>. I still get comments through Akismet and Bad Behavior and legitimate comments get false positived (yeah, positived could be a word) by Akismet.</p>
<p>One thing I like about Bad Behavior is that it doesn&#8217;t actually stop bots from commenting directly; it stops bots from even seeing your blog (so they don&#8217;t even know about the comment form). To protect against false positives, a user being flagged as a bot, there&#8217;s a confirmation screen just in case. (I admit the confirmation scenario is pretty weak; but until I can come up with something more clever it&#8217;ll have to do.)</p>
<p>Before I installed the Bad Behavior plugin into my blog, I was getting around 30 spam comments a day. Almost half of my reported traffic was spam! Everyday I would log into my admin and have to scan every comment to see what was real and what wasn&#8217;t. </p>
<p>Even though this process only took a few minutes it was still disruptive to my day. Plus, you know, $Eric = &#8216;Lazy&#8217; so I try to keep my mental load low. This was just too much to do every, single, day.</p>
<p>I had used Bad Behavior on a client site once, and was pretty happy with it&#8217;s results, so I installed the Bad Behavior WordPress plugin. My comment spam dropped to about 2 a week. I&#8217;m not exaggerating.</p>
<p>As to the IP issue; also not ideal but it&#8217;s not the sole criteria to block something. Bad Behavior also looks at the headers and stuff (stuff <em>is the</em> technical term) which are also pretty easy to manipulate. </p>
<p>You just have to keep in mind that programmers who work for spammers are usually the bottom of the barrel. Seriously, the good programmers get better jobs so the majority of the spammers are pretty bad and don&#8217;t implement the advanced techniques to hide their tracks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eldris</title>
		<link>http://blog.ericlamb.net/2009/05/the-bad-behavior-spam-blocker-part-1/comment-page-1/#comment-943</link>
		<dc:creator>eldris</dc:creator>
		<pubDate>Fri, 08 May 2009 17:31:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ericlamb.net/?p=1504#comment-943</guid>
		<description>I agree with you that registration is a bad option to prevent spam. I find that I will just walk away from commenting on a blog if a see a registration form (with the exception of cnet, who have a really nice registration form that doesn&#039;t take you away from the post, although you do have to deal with an activation email which sort of defeats the point).

I feel almost sorry for bloggers who have registration forms, because they probably lose a lot of comments that way, and commenting provides a good way for readers to stay interested in a blog.

At least there don&#039;t seem to be many blogs around using captchas. I&#039;ve started to get really fed up with captchas; there seems to be a new breed about which I find difficult to read. It&#039;s one thing stopping bots, but if a human can&#039;t use it then you&#039;ve failed anyway.


I am tempted to install Bad Behaviour on my blog, but I&#039;m not keen on the fact that it stops them from even commenting. What I like about Akismet is that I can check the spam to see if it caught something it shouldn&#039;t, which it actually did to a pingback just last week. I find myself not being able to trust automated spam blockers to be 100% accurate. It&#039;s fine if I can correct the mistake like with the pingback, but if I lost a reader because it mistook them to be a spammer, I&#039;d be sad.

They&#039;re being pretty lazy with that log set up. I&#039;m still pretty new to wordpress, but other plugins seem to manage. They could at least have it write the logs to files and tell you how to convert it to database use.


*short interlude*

I just had a look at how they say it works. It&#039;s an interesting approach to be sure, but it still doesn&#039;t convince me. They use IP addresses, which can change and be re-used by other people (I think?). All I have to do to change my IP adress is re-connect my broadband. They also use header data etc, but from your poll exploit post http://blog.ericlamb.net/2009/04/how-to-exploit-an-online-poll/ it seems this info can be changed, which I&#039;d have thought spammers would do as much as possible.

But, people use it and say it&#039;s effective. Haha, I just don&#039;t know what to think about this one :D I&#039;m sure spammers could get around it if they wanted to though. Please let me know if I&#039;m mistaken about any of this though. If my knowledge is flawed I must fix it ^_^</description>
		<content:encoded><![CDATA[<p>I agree with you that registration is a bad option to prevent spam. I find that I will just walk away from commenting on a blog if a see a registration form (with the exception of cnet, who have a really nice registration form that doesn&#8217;t take you away from the post, although you do have to deal with an activation email which sort of defeats the point).</p>
<p>I feel almost sorry for bloggers who have registration forms, because they probably lose a lot of comments that way, and commenting provides a good way for readers to stay interested in a blog.</p>
<p>At least there don&#8217;t seem to be many blogs around using captchas. I&#8217;ve started to get really fed up with captchas; there seems to be a new breed about which I find difficult to read. It&#8217;s one thing stopping bots, but if a human can&#8217;t use it then you&#8217;ve failed anyway.</p>
<p>I am tempted to install Bad Behaviour on my blog, but I&#8217;m not keen on the fact that it stops them from even commenting. What I like about Akismet is that I can check the spam to see if it caught something it shouldn&#8217;t, which it actually did to a pingback just last week. I find myself not being able to trust automated spam blockers to be 100% accurate. It&#8217;s fine if I can correct the mistake like with the pingback, but if I lost a reader because it mistook them to be a spammer, I&#8217;d be sad.</p>
<p>They&#8217;re being pretty lazy with that log set up. I&#8217;m still pretty new to wordpress, but other plugins seem to manage. They could at least have it write the logs to files and tell you how to convert it to database use.</p>
<p>*short interlude*</p>
<p>I just had a look at how they say it works. It&#8217;s an interesting approach to be sure, but it still doesn&#8217;t convince me. They use IP addresses, which can change and be re-used by other people (I think?). All I have to do to change my IP adress is re-connect my broadband. They also use header data etc, but from your poll exploit post <a href="http://blog.ericlamb.net/2009/04/how-to-exploit-an-online-poll/" onclick="return TrackClick('http%3A%2F%2Fblog.ericlamb.net%2F2009%2F04%2Fhow-to-exploit-an-online-poll%2F','http%3A%2F%2Fblog.ericlamb.net%2F2009%2F04%2Fhow-to-exploit-an-online-poll%2F')" rel="nofollow">http://blog.ericlamb.net/2009/04/how-to-exploit-an-online-poll/</a> it seems this info can be changed, which I&#8217;d have thought spammers would do as much as possible.</p>
<p>But, people use it and say it&#8217;s effective. Haha, I just don&#8217;t know what to think about this one <img src='http://blog.ericlamb.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  I&#8217;m sure spammers could get around it if they wanted to though. Please let me know if I&#8217;m mistaken about any of this though. If my knowledge is flawed I must fix it ^_^</p>
]]></content:encoded>
	</item>
</channel>
</rss>

