3 ms·
I used to have comments and a xapian index/engine on my website, something I wish every website would have. To share my experience, I eventually removed both.
by wakeupcall 3y ago
I used to have comments and a xapian index/engine on my website, something I wish every website would have. To share my experience, I eventually removed both.
The xapian index was both faster, more accurate and up to date than any public search engine. Nobody besides myself ever used it, often returning from a google site: search instead.
Things change if you have the wiki as a personal information repository and use search yourself, as the OP points out. I still have that, but I keep this private as I also index other private stuff and can't make the two separate.
And because I have a local mirror of the archive anyway, I'm often faster grepping than using search (it's just not big enough).
I also had fully open/anonymous comments. As you might expect, this gets spam almost instantly nowadays. I switched those behind a login wall, but I realized after a few years that I wouldn't create an account on a random website myself just to post a comment. For anything more involved than a quick comment I just dropped an email to the author[1].
Right now I fear that under GDPR those public comments would just be a liability.
[1] if the author is kind enough to do so instead of dropping a twitter handle...
- layer8 3y agoHidden fields seem to work pretty well: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=spam%20hidden%20field&sort=byDate&type=comment https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
- wakeupcall 3y agoIt only worked for so long. I had spammers post with the hidden field after being targeted. I then switched the field to a hashed simple time-based value, to which they responded to by just fetching the page to get the value, and posting it back. The posted content was often in two categories: links with stuffed keywords, or some common framework exploit (generally fetching a remote resource to test for exploitability). While marginally entertaining in the beginning, it's just a waste of time unless you want to create some form of engagement within a blog..
- layer8 3y ago> I had spammers post with the hidden field after being targeted. Don’t they usually set a value on the hidden field? One approach is to check that no value is submitted for the field.
- wakeupcall 3y agoI checked for a specific default value (server-generated), so having no-value or a random value both wouldn't work. It is pretty effective in most cases at evading most bots and dumb attempts, but it's also trivial to defeat if you're being targeted.