Showing posts with label Commenting Problems. Show all posts
Showing posts with label Commenting Problems. Show all posts

Tuesday, January 24, 2017

Comment Publishing Preview, And "Error 400"

We're seeing a problem with Blogger Hosted Comments - and "Bad Request Error 400", following the use of the comment "Preview" feature.

When a blog owner or reader composes a long or important comment, use of the Preview feature is normal. Right now, after hitting "Publish", following a successful Preview, one frequently sees the bad news.
Bad Request
Error 400
There is a workaround for this annoyance - and it's not difficult to use.

Until Blogger Engineers fix the "Error 400" problem, there is a workaround - and the workaround adds very little time to comment publishing.

The most obvious alternative would be to not use Preview. But how well can you eyeball your comment, without Preview?

If you find it inconvenient to eyeball check a comment without using Preview, it's a small effort to copy then paste, before Publishing. Just a little planning, before composing, lets you copy then paste.


OMG, where is my comment? All my work, gone??



Opening a new tab / window lets you publish, after the preview / edit cycles (and avoid the "Error 400"), when composing an important or long comment.


Here's the key to the workaround. "Open link in new tab" - a context menu option, for any link.

With most browsers, you'll either "Alt" click or right click on the link, to get the context menu.



  1. Recover the comment content, if you're looking at the "Error 400".
  2. Open the post, where a comment is needed.
  3. Open a comment composition window, in a new tab / window.
  4. Compose the comment, carefully edited.
  5. When satisfied by the Preview display, click Edit once more.
  6. Copy the edited comment.
  7. Close that browser tab / window.
  8. Open a comment composition window, again.
  9. Immediately paste into the new comment composition window.
  10. Immediately Publish.
  11. Done.

Recover the comment content, if you're looking at the "Error 400".

If you're looking at the "Error 400" display, right now, refresh the display and follow the prompts. Recover the comment composition window, with your work in progress. Skip ahead, to Step #6.

Open the post, where a comment is needed.

Start with a post - and the "Post a Comment" link at the bottom of the post.

Open a comment composition window, in a new tab / window.

Click on the "Post a Comment" link - and use the "Open in new tab / window" browser option. With most browsers, you'll either "Alt" click or right click on the link, to get the context menu - and the "Open in new tab" / "Open in new window" option.

Compose the comment, carefully edited.

Use Preview and Edit, and the composition window, as necessary. Compose, preview, and edit - until your comment is properly phrased.

When satisfied by the Preview display, click Edit once more.

If it's an important or long comment, you'll use the Preview - Edit sequence, a few times. Just finish, with a final "Edit".

Copy the edited comment.

From the comment composition window, hit "Ctrl - A" to select everything as edited, then "Ctrl - C" to copy.

Close that browser tab / window.

Close the tab / window - and bid farewell to the carefully written content, and the Bad Request.

Open a comment composition window, again.

Click on "Post a Comment" from the displayed post - again, using "New tab / window". You will have an empty comment composition window.

Immediately paste into the new comment composition window.

Immediately paste the copied comment ("Ctrl - V") into the empty comment composition window.

Immediately Publish.

You already previewed and edited your comment - now, Publish.

Done.

The comment publishes - and, you're done.

Do this a few times - you'll see that this adds maybe 30 seconds to the comment composition / preview / edit cycle.

How long does it take to compose (preview, edit) a comment, to your liking? I take a lot longer than 30 seconds.

Just copy, close, open, paste, and publish.

And you're done.



Publishing a comment, using #Blogger hosted comments, following use of the Preview feature, subjects us to "Bad Request Error 400". Using a browser supplied new tab / window, and copying then pasting, we can workaround the "Error 400".

Thursday, July 14, 2016

The CAPTCHA Continues As A Challenge

This month, we are again seeing evidence of recent security changes by Microsoft. We see signs of continued frustration, in the process of publishing comments - and publishing posts, as part of the Import process.

In the process of diagnosing an apparent comment publishing problem, I ventured into the comment publishing experience, yet again.

I temporarily tweaked commenting permissions for this blog, to allow anonymous comments and to require the CAPTCHA.

With CAPTCHA required, I published a test comment to my earlier post in this blog.


I did my best - which was not good enough.



CAPTCHA solving continues, as a challenge.


I entered a test comment, and made appropriate selections.




I got a challenge.

"Select all the food."




I did my best.




Apparently, my best was not enough.

"Select all images with a store front."




I tried again. Not all images here were completely obvious, either.




My second try was successful.



Hmm.

Select all the food.

Zoom in on the fourth image, above - and tell me which pictures, that I did not select, are food? To whom? Will zooming always improve chances of success?

CAPTCHA solving, as spam interdiction, will always lead to frustration.

There will be cultural issues - and resolution problems - with CAPTCHAs. This version of the CAPTCHA beats the one from several years ago - but still will cause frustration.

And need I again point out - will require proper filter tuning, on each computer used. Note that ongoing changes by Microsoft are currently affecting publishing comments - and publishing posts during the Import process.

And our experience may very, depending upon many different details, varying by blog, by computer, and by person. My sympathies to all who must deal with spam - and with spam interdiction.



The CAPTCHA continues to be an unavoidable element in comment publishing and other episodes of #Blogger life. And like life, some episodes are more pleasant than others.

Thursday, June 9, 2016

Inaccessible Comments, On Some Popular Posts

Viewing comments, on some popular blogs, one may get the idea that not as many comments are being published, as are immediately visible.

With a large comment complement, comments are paginated - with some comments hidden behind a link, captioned "Load more". The "Load more" link is JavaScript based - and there is a problem.

The "Load more" link does not always work, on all blogs.

Comments on some blogs may be unreadable - with the "Load more" link not operational.


Some posts never display all comments.




Look at the bottom of the page, below the post.




And there is the "Load more" link.




And the link, as seen when one mouse over it, is shown to be JavaScript based.




And clicking on the link yields the caption "Loading ...".




And "Loading ..." never goes away - and we get no view of the missing comments.



I've seen this problem with blogs using both dynamic and non dynamic templates.

Both dynamic templates, and non dynamic templates, appear to use comments paginated behind "Load more" - and may exhibit this problem. I've seen this problem, reported in Blogger Help Forum: Get Help with an Issue, for both template types.

I have reproduced this problem, using two blogs.

Here are two recently reported cases, reproduced in my testing today. I do not know how long both cases may be active.

http://slifkinchallenge.blogspot.com/2016/05/thank-you-yehoshua-duker-and-yosef.html
https://productforums.google.com/d/topic/blogger/RotUfv8AwuU/discussion

http://istanbulkonstantinopel.blogspot.com/2014/03/study-in-turkey-2.html
https://productforums.google.com/d/topic/blogger/7Yau3KKR9mo/discussion


Noting that both blogs are (natively) published in countries that are subject to local country codes (Israel and Turkey, respectively), I will deny that to be a simple affinity - since I viewed both blogs from my browser, as "blogspot.com", as I reproduced the problem. That said, that is an interesting coincidence, no?

There are several possible causes of this problem. Adding the above observation, some of these causes may be more or less relevant.

  • Comments feed setting.
  • Comment feed content / corruption.
  • Cookie / script filters.
  • HTTPS Redirect.
  • Occam's Razor.
  • Post template corruption.

Comments feed setting.

Features like the comment reply option, and blogs published to dynamic templates, require a full comment feed. It's possible that comment pagination, behind JavaScript links, is similarly sensitive to the comments feed setting.

This detail will affect everybody - both blog owner(s) and reader(s) alike. And it will probably affect all posts, uniformly.

The solution for this problem would involve checking - and correcting - the comments and feed settings, for the blogs involved.

Comment feed content / corruption.

Similar to the problem with the Blogger blog post published location, it's possible that some unknown detail in the data could interfere with script functionality.

If the problem involves content in one post - or a comment on one post, it's possible that comments for one post could be affected; but other posts could paginate comments successfully.

This detail would probably affect everybody, uniformly.

The solution for this problem will require determining what feed content detail causes the problem. This will probably involve affinity diagnosis.

Cookie / script filters.

Any problem which involves a JavaScript based link, both cookies and scripts are always going to be involved. Any filter that interferes with either cookies (identity) or scripts (link functionality) will always be a possibility.

Filters may affect either blog owners and / or blog readers, uniquely. A problem that involves some owners / readers will likely involve filters.

Thanks to the effect of country local domains, cookie / script filters may affect individuals geographically.

The solution for this problem is to check / open up script filters - and then check / open up cookie filters.

HTTPS Redirect.

Both blogs, identified above, appear to not be using the "HTTPS Redirect" option. It's not impossible that this is another feature, broken by the SSL Rollout.

Occam's Razor.

Considering the most simple alternative, is it possible that paginated comments are simply inoperative? Maybe, because of (or incidentally involving) the SSL Rollout??

Post template corruption.

Comments are part of the post template. It's likely that proper comment functionality also requires a clean post template. This detail will probably affect everybody - though it's possible that there could be code that is sensitive to some owners / readers, but not others.

The solution for this problem is to reset the post template, on the blogs involved.

The bottom line.

This problem, if not incidentally solved by a Blogger code change, will probably not be diagnosed, immediately.

More examples of this symptom are badly needed. Right now, we have seen only a handful of people with blogs that are popular - and generate comments in sufficient volume - and have reported this problem.



Some #Blogger blog owners, who publish blogs with posts that receive large volumes of comments, report inability to display all comments published. Comments, when displayed in large volumes, are paginated behind JavaScript based links - and some links, when clicked, don't seem to work.

https://productforums.google.com/d/topic/blogger/7Yau3KKR9mo/discussion
https://productforums.google.com/d/topic/blogger/RotUfv8AwuU/discussion

Monday, May 30, 2016

Microsoft Windows Security Updates, May 2016

If you use a computer that runs Microsoft Windows, you may have been affected by Microsoft supplied updates, distributed 3 weeks ago.

May 10 was the day termed "Patch Tuesday" - the day when Microsoft releases important security related patches, to its various Internet updated products. During the 3 weeks after May 10, we've seen a significant number of security related discussions, in Blogger Help Forum: Get Help with an Issue.

It appears that Microsoft updates, for May 2016, affect use of Blogger.

The Microsoft Security updates, applied May 2016, appear to have affected various Blogger features, that are known to be vulnerable to layered security.

  • CAPTCHA visibility when daily post limit is exceeded.
  • Publishing comments, or replying to published comments.
  • Quick Edit icons.
  • Followers / Reading List maintenance.
  • Stats self initiated pageviews.

All of these features are known to be affected by cookie filters, and / or by script filters.

If you are using a computer that runs either Microsoft Windows 7 or Windows 10, and you are experiencing a problem with publishing comments, or with using Quick Edit, or with blocking your own views in Stats, or similar problems, you may want to check your cookie and script filters.

I note that some of the reports mention the browser used as Chrome or Firefox. You'll want to check filter settings in Windows Security Essentials.

Being realistic, it's also possible that Microsoft broke something within Windows - but we'll have to wait patiently, for them to admit that.

If you need different or more advice, please start a new topic in Blogger Help Forum: Get Help with an Issue.



Microsoft released monthly security updates May 10, 2016 - and since that date, there have been a number of security filter related issues, reported in Blogger Help Forum. It appears that the the Microsoft Updates involve cookie or script filters, which affect use of Blogger.


Friday, November 28, 2014

Blogger Blog Readers Unable To Comment, Using OpenID Accounts Hosted By WordPress

We're seeing a scattered collection of reports, mentioning problems publishing comments, using OpenID authentication.

This problem appears to be related to the Blogger rollout of SSL support, for our blogs, which is currently in progress. SSL, or Secure Socket Layer, represents the next step in blog / website security - a step which the Internet community has been taking, for many years.

Blogger has been using SSL (aka "HTTPS" login), in their dashboard, for several years.
https://www.blogger.com
That's a secure Blogger login. The problem with Blogger using SSL in our blogs is that moving to SSL requires care, to avoid confusing our readers. Lack of care will subject our readers to the well known "mixed mode" warnings.
This site has insecure content.
Only secure content is displayed.
Firefox has blocked content that isn't secure.
These are several examples of what were normal, years ago, on many websites. Blogger does not want our readers subject to needless confusion, from these warnings.

Blogger blog owners have been asking, for years, that Blogger support SSL in BlogSpot (and our custom domains).

FaceBook upgraded to SSL, in 2013 - and saw problems with Blogger content.

Last year, FaceBook upgraded to SSL. Blogger blog owners, who were also FaceBook members, watched their Walls, which contained HTTP links to their Blogger blogs, show the "mixed mode" warnings.
The real issues begin to arise, however, when your application must include assets served by servers which also do not support SSL.
...
We’ve all experienced “mixed mode” warnings, with some browsers being much more annoying about them than others. "Mixed mode" means you requested a page over SSL, but some of the resources needed to fully render that page are only available over unencrypted HTTP.

Blogger is offering the option for us to upgrade our blogs, this year.

Now, Blogger is upgrading, so our blogs may (optionally) support the SSL protocol - and not confuse FaceBook members, who post links to our blogs. To avoid the "mixed mode" warnings, which would confuse our readers, they are upgrading all Blogger processes, including OpenID authentication, to support SSL.

The Blogger upgrade has exposed a WordPress inconsistency.

Just as FaceBook upgrading to SSL helped to cause Blogger to upgrade, so is Blogger upgrading to SSL exposing an inconsistency in WordPress use of SSL, for OpenID authentication.
The problem in my case (and maybe in others as well) seems to be that https://yourblog.wordpress.com is send for verification to the OpenId server. This is what I could figure out from the URL. If you than manually replace HTTPS with HTTP, it works.
This comment suggests that WordPress, which in general is using SSL security, has an OpenID server that has not been upgraded.

WordPress needs to check their OpenID servers.

So now, Blogger has to wait for WordPress to fall into step, consistently. Until WordPress upgrades their OpenID server, people who want to use a WordPress OpenID account, to comment on our blogs, will have to select "OpenID", instead of "WordPress" - then enter the WordPress OpenID URL, as
HTTP://whatever.wordpress.com
And wait for WordPress to upgrade their server.

Sunday, November 23, 2014

Change Per Post Comment Settings, One Post At A Time

Occasionally, we have a blog owner trying to enable commenting, on a blog - and being unsuccessful diagnosing commenting problems.

Checking the per blog comment settings, in the the dashboard menu under Settings - Posts and comments, there's no obvious problem. The problem, in some cases, is in the per post settings, in the Post Editor "Post settings - Options" wizard - but not all posts will have a problem.

The "Reader comments" setting, for any new post, is taken from the setting for the previously published post. If you publish a post today, with "Reader comments" selected as "Don't allow", the next post will also be set to "Don't allow" - unless you change the setting, before publishing. Similarly, if it's set to "Allow", the next post published will have it set to "Allow".
  • Allow
  • Don't allow
That's the choices, for each new post.

If the setting for any post is wrong, according to your policy, it's up to you to change the setting, for that post.

Since the per post setting overrides the per blog setting, any existing posts, with the setting "Don't allow", will not allow comments. To change this, you have to edit each post, one by one, and change the setting.

If the setting is "Allow", and you want to disable comments, you have to change the per post setting, one post at a time. Again, any new posts will then have the setting "Don't allow" - but any existing posts will have to be changed, one post at a time.





If you occasionally disable comments, check this setting before you publish a new post - and make sure that comments are enabled, when appropriate.



If you backdate a post, and publish it before any previously published posts, the setting for the previously published posts won't change. If this creates a range of posts, with inconsistent settings - some allowing comments, the others not allowing comments - you'll still have to change the setting as you wish, for each post, one by one.

If the setting for a post is currently "Allow", and a post has comments, you'll have 3 options for that post.
  • Allow
  • Don't allow, show existing
  • Don't allow, hide existing
That's the choices, for each post with comments.

If you're in the habit of changing the comment setting for various posts, you'll want to check the setting, for each new post - and make sure that it's appropriate. Better that, then to have to change a whole bunch of posts, one by one, later.

Tuesday, November 18, 2014

Comments, Owner Choices, And Reader Choices

Much of what we do in life - and what we do when using Blogger - is based upon, and limited by, choice.

Some choices we get to make, for ourselves. Other choices are made for us, by people who make their own choices.

Some blog owners do not want their readers to have to login to Blogger, to comment on their blogs. Other blog owners do not want their readers to have to solve a CAPTCHA, to comment on their blogs.

A few blog owners do not want their readers to have to do either.
It seems anyone who wishes to leave a comment, will have to do some form of login, either via Google or a CAPTCHA, to do so! Is there a reason for this, would it not be easier, for anyone to just leave a comment?
And the answer here is simple.
It would be easier, if neither were required.
But reality - involving activity by spammers, and activity to counter spammers - leaves some of us with less choices.

Long ago, Blogger allowed anonymous comments, without a CAPTCHA to solve. Spammers benefited from that possibility.

Later, Blogger added the ezCAPTCHA, to be required at the owners decision. Some owners chose to not select the CAPTCHA, because their readers were inconvenienced. Spammers continued to benefit from blogs which allowed anonymous comments, and no CAPTCHA.

Recently, Blogger added the non optional reCAPTCHA. This requires anybody not logged in to have the choice - login, or solve a CAPTCHA.

Unfortunately, the latter change made the third party cookie filter issue more critical. People who are already logged in, but are subject to third party cookie filtering, have to login, or solve a CAPTCHA. This requirement may vary, according to the variant of the commenting form, used by the blog.

Now, a blog owner has 4 choices, to control anonymous comments.
  1. Don't allow anonymous comments, and don't require a CAPTCHA. People who are not logged in will have to login, to comment.
  2. Don't allow anonymous comments, but require a CAPTCHA. People who have not logged in will have to login, and solve a CAPTCHA.
  3. Allow anonymous comments, and don't require a CAPTCHA. People who have not logged in will have to either login, or solve a CAPTCHA.
  4. Allow anonymous comments, and require a CAPTCHA. People who are not logged in will have to solve a CAPTCHA.

Some people will have to either login, or solve a CAPTCHA, to comment. Depending upon what choices are made by the blog owner, the readers may have any 2 of 3 choices.
  1. Solve a non owner optional reCAPTCHA.
  2. Solve an owner optional ezCAPTCHA.
  3. Login.
You'll like the ezCAPTCHA a lot more than the reCAPTCHA.

People who are logged in to Blogger / Google, and are not subject to third party cookie filters, may not see a CAPTCHA - and will not have to login to comment. People who are logged in, but are subject to third party cookie filters, will have to either login, or solve a CAPTCHA.

Owners of blogs which attract readers, who choose to maintain their cookie filters, will benefit more from the new CAPTCHA, than owners of blogs which attract readers who do not choose - or do not care - to maintain their cookie filters.

To make the choices easier to understand, Blogger would have to make "Require CAPTCHA" a binary option, for at least 3 comment authentication levels.
  1. Anonymous.
    • Require CAPTCHA.
    • Don't require CAPTCHA.
  2. OpenID.
    • Require CAPTCHA.
    • Don't require CAPTCHA.
  3. Google account.
    • Require CAPTCHA.
    • Don't require CAPTCHA.
  4. Members.
    • Require CAPTCHA.
    • Don't require CAPTCHA.

If Blogger were to offer this binary option, too many owners would select "Anonymous" / "Don't require CAPTCHA" - and spammers would continue to flood the spam filters - as they were, before the latest update.

As long as spammers choose to do business - and choose to target our blogs, in their business - our choices, as blog owners and readers, will be limited.

>> Top

Friday, November 14, 2014

Comments Posted Use "noreply" Email Addresses

Recently, we've noted a number of complaints about Blogger commenting, in Blogger Help Forum: Something Is Broken
.My comments all use a "noreply" email address, instead of my actual email address. How do I have people email their replies to my comments?
This appears to be one more way which Blogger is trying to safeguard our Blogger accounts and blogs, from malicious, technically astute blog thieves.

Some time ago, we observed that this precaution appeared to be unique to Blogger accounts which used Google and Google+ profiles - and did not involve Blogger profiles.

It appears that this is now universal, and includes Blogger profiles, as well as Google / Google+ profiles. It's likely that the noreply email addresses are being offered to keep more blog readers from, inadvertently, exposing their email addresses to email mining techniques.

In remembering the long ago discovered "nice blog" spam, it's possible that "nice blog" spam was originally developed to help the spammers gather email addresses, using very innovative technique.

All that a spammer has to do is to post a "nice blog" comment, select "Email follow-up comments to me" - then watch as the Inbox fills up with follow up comments from bloggers, willingly giving up their email addresses to every stranger also selecting "Email follow-up comments to me", in that comment thread.

The people willingly providing their email addresses, to the world in general, are perfect targets for hackers later trying to brute force access to the Blogger accounts, starting from the provided email addresses. Use of the "no-reply" email address prevents this type of mischief - and reduces the workload of Google Security, as they would otherwise have to verify account / blog integrity, for hacked accounts and blogs.

For even more protection (which is not a bad idea, in any case), consider using Google 2-Step Verification, to protect your Blogger / Google account from hacking.

>> Top

Tuesday, November 11, 2014

The "Reply" Option, For Embedded Comments

The option provided some time ago, to the embedded comment form, to allow "threaded" comments, is becoming quite popular.

Unfortunately, the "Reply" link does not always work. Blog owners and readers alike complain.
I click on "Reply", and nothing happens!
This problem appears to have accelerated recently, possibly resulting from the hasty rollout of the new anonymous comments CAPTCHA - but there are other less obvious possibilities, too.

The threaded comments "Reply" feature, a seemingly minor addition to the Blogger code base, can have problems with a number of issues.

  • A Full Blog Feed.
  • An up to date post template,
  • The Google "One account" login, and cookie filtering.
  • The recent addition of the anonymous commenting CAPTCHA.
  • The threaded comments script, and recent script filter updates.

A Full blog feed is required.

Many blog owners are not aware that the "Reply" option won't be available, without a Full Blog Feed. Go to the dashboard, and look at "Allow Blog Feed", under Settings - Other - Site feed.

For threaded comments, you will need a Full Blog Feed (for both comments and posts) - and this will exclude private blogs.


Any "Allow Blog Feed" selection, other than "Full", will be a problem.



An up to date post template is a good idea.

Threaded comments, like every other post and comment feature, works best on an up to date post template. Any time threaded comments stops working, and you have not changed the blog feed, try resetting the post template. Now, here's hoping that you have not made extensive post template tweaks.

The identity of the person who wants to reply is useful.

Threaded Blogger hosted comments code, like threaded Google+ hosted comments, other commenting scripts, and many other Blogger features, needs access to the login cookie, to identify the person preparing to comment. Because of the use of the Google "One account" login, "third party" cookie filters must be examined.

Anything that interferes with the CAPTCHA will be a problem.

The recent addition of the anonymous comment CAPTCHA, appears to have caused some problems. This may be an matter for Blogger Engineering to correct.

Anything that interferes with scripts will be a big problem.

All Blogger scripts, including the script which services the "Reply" link, are subject to script filtering. Script filters are subject to update, on every different client computer - generally without notice to the computer owner. Always check script filters.

Blog owners and readers, alike, need to be aware of the issues, to use Blogger effectively. Threaded comments are no exception to this requirement.

Tuesday, October 28, 2014

Comments And Cookie Filters - October 2014

The new, mandatory CAPTCHA form, for blog readers wishing to comment anonymously, has been in service for just under a week.

We're seeing a variety of problems, reported in Blogger Help Forum: Get Help with an Issue, by blog owners and readers alike.

Long ago, for blogs with readers who were not really comfortable with maintaining security on their computers, we would recommend changing comment form placement.

The full page (or the slightly less preferable popup window) comment form was more usable, with readers who do not know how to properly maintain cookie and script filters. With recent changes in Blogger and Google, all Blogger comment forms are now vulnerable to inappropriate filters.
  • Use of the Google "One account" login creates login cookies under "google.com" - not "blogger.com".
  • Publishing blogs to custom domains - not "blogspot.com" - makes cookie access "third party".
  • Referencing blogs from countries subject to country code aliasing - not as "blogspot.com" - makes cookie access "third party".
  • The new, mandatory commenting CAPTCHA form, part of all Blogger comment form placement options, makes cookie access very important.
All of these issues, considered together, makes proper third party cookie filtering even more critical, than it has been, in the past - and makes new Blogger features more problematic.

The Google "One account" login, at "google.com", is now used by many blog owners and readers - instead of the Blogger native login, at "blogger.com". When the "blogger.com" login was used, cookies created under "blogger.com" were not as vulnerable, to cookie filters.

Whether used under "blogspot.com", or whatever country code alias or custom domain is in use (for the embedded comment form) - or under "blogger.com" (for the full page and popup window comment forms) - login cookies created under "google.com" (by the Google "One account" login) are vulnerable to "third party" cookie filters.

Blogs published to custom domains are becoming more and more popular. All blogs published to custom domains, which use the embedded comment form, are vulnerable to "third party" cookie filters.

Blogs referenced under country code aliasing are becoming more normal. All blogs subject to country code alias redirection are vulnerable to "third party" cookie filters.

The new, mandatory commenting CAPTCHA form needs to access the Blogger / Google login cookie - so blog readers, who are logged in to Blogger / Google, will not be subject to the CAPTCHA. The embedded, full page, and popup window forms are equally vulnerable to "third party" cookie filters, given the above discussed issues.

Thanks to the Google "One account" login, as Blogger is made a way of life to more of a reader population who have no interest in maintaining security on their computer, these issues will become more problematic.

>> Top

Sunday, October 26, 2014

The New Commenting CAPTCHA Is Inconsistent

The new CAPTCHA, added by Blogger last week to restrict spam in anonymous comments, is already showing signs of unwanted effect, with some blogs.

Besides making the commenting sequence more complicated, the sequence, in general, is inconsistent. Differences in the sequence, when compared between the three commenting form placement options (embedded, popup, and full page), varied by the original CAPTCHA screening option, and the moderation option, have been noted. And how many readers, commenting on their favourite blog, will think of hitting "Publish" with "Google account" selected, to login and avoid the CAPTCHA?

The CAPTCHA form itself will discourage comments, being made by the casual blog reader, against many blogs. And the CAPTCHA, as added to all three comment forms, now makes cookie filtering issues equally critical, for the embedded, popup, and full page forms, alike.

As designed, CAPTCHA screening should simply affect people who wish to publish comments, anonymously.

Some blogs may require the CAPTCHA, for anonymous and authenticated comments, alike - when a reader is not logged in to Blogger. Other blogs may allow people to avoid the CAPTCHA, altogether - who even comment, anonymously, without solving a CAPTCHA, when logged in.

With some blogs, you may hit the "Publish" button immediately, and go straight to login - and other times, be stopped by the refusal
Comment should not be empty
Alternately, you may compose your comment, then select "Google account" - and upon returning from login, find an empty comment window.

Depending upon which comment placement option / template type is in use, you may see any of those inconsistencies.
  • Dynamic template.
  • Embedded.
  • Full page.
  • Pop-up window.
Each of these different comment forms variants has its own peculiarities.

These inconsistencies are more critical, because some readers filter cookies, improperly. With third party cookies filtered, the login status is not correctly identified by the commenting process - and the CAPTCHA may be required where it should not apply.

We may even see, with enough different people trying to comment, a return of the commenting login loop - where people login, repeatedly, but are denied by the CAPTCHA form in the commenting process.

Making things still worse, the CAPTCHA form is nasty. People who are less technically astute, and who have problems maintaining the filters on their computer, may be less tolerant of the CAPTCHA process - and may simply find other blogs, maybe outside Blogger / Google in general, which are more permissive.

The need for the CAPTCHA form, in general, is real - but the implementation needs improvement. Until unimproved, many Blogger blogs will feel negative effects.

>> Top

Wednesday, September 17, 2014

Blogger Browser Support, And Layered Security

The official Blogger browser compatibility reference, Compatible browser and operating systems states Blogger requirements, very succinctly.
To use Blogger, your browser must allow cookies and have JavaScript turned on.
This is a very brief hint of Blogger browser support policy.

Use of Blogger includes various activities.
  • Moderate Blogger hosted comments.
  • Post comments, as a blog reader.
  • Edit, preview, and publish posts.
  • View Stats.
  • Use the Template Designer.
Each of these activities, and more, require cookies and scripts - and each are vulnerable to improperly setup filters.

As Blogger implies, both cookies and scripts are vulnerable to being disabled (turned off) - although the term "turned on" suggests that there is one single setting, possibly affecting each individual cookie or script. Considering the effects of layered security, we know this won't always be true.

Layered security can include settings in multiple components.
  1. Native browser settings.
  2. Various browser add-ons, extensions, and plugins.
  3. Security accessories, installed on the computer, outside the browser.
  4. Network appliances, installed outside the computer.
Any of these accessories and components can have filters, which can block cookies and / or scripts.

Filters are serial in nature. If any one filter blocks a necessary cookie or script, that cookie or script becomes unavailable to the Blogger feature in question.
  • You can't moderate Blogger hosted comments.
  • You can't publish a comment.
  • You can't publish a post (use Preview).
  • You can't view Stats (or exclude your own pageviews).
  • You can't use the Template Designer (or Live Preview).
Each JavaScript filter can affect a small portion of one Blogger feature. Sometimes, the feature will load, then terminate with another infamous "bX code", or a monolithic error message. Other times, the feature may not even load, and you get a blank screen.

As noted several times, just because it worked yesterday, that does not mean that it will work today. Every filter is subject to update, by its creator. And both BlogSpot published blogs, and non BlogSpot published blogs, are subject to different, and ever changing filters.

>> Top

Wednesday, September 10, 2014

Comments And Layered Security

One of the most common complaints, seen regularly in Blogger Help Forum: Something Is Broken, involves publication and visibility of comments.
Why can't I publish comments, on some blogs?
or
Why can't I see my comments, after I publish them?
or even
Why do my blog posts show no comments?
These are questions asked by blog readers and owners, alike. The answers all start with security filters and settings.

Security filters and settings affect the ability for you, and your readers, to use commenting, on your blog.

Comment Form Style

The majority of the problems, with commenting and filters, involve blogs which use the Post Page ("Embedded") comment form. Use of the embedded form requires third party cookies, on the reader computers.

The Full Page form is least vulnerable (though not totally so), of the 3 form styles. Embedded, Full Page, and Pop Up comment forms are all vulnerable, to differing extents, because of the different blogs, that attract different reader populations, each with differing abilities and needs to maintain security on their own computers.

The problems with comments involve the clients (ie, the blog readers), their computers, and their choices, reacting to the options chosen by the blog owners.

Security Accessories

Every different computer, accessing the Internet, has a different combination of security accessories. Every different security accessory will have its own filters - and be subject to updates, by the provider. And every different filter will be triggered, from time to time, by different components in the various Blogger (and Google+) comment scripts.

The commenting process - and accompanying security problems - involves many different details, besides comment form placement.

The blog URL, and the geographical location of the reader, will trigger filters. Both blogs subject to country code alias redirection, and those using custom domain publishing, will be affected by filters, in different ways. Both involve blogs not accessed as "blogspot.com".

Commenting Options

Authentication options, which are selectable by the blog owners, will vary.

  • Anyone (no authentication required).
  • Google / OpenID account.
  • Google account only.
  • Blog members only.

Within those 4 levels of authentication, the blog reader will have 1 to 3 choices. Each of those choices (by the blog readers), combined with each of those options (chosen by the blog owners), will involve different sections of code.

Besides the authentication choices and options, there are options (for the blog owner) to include CAPTCHA verification, and to include comment moderation and notification. Again, different sections of code will be involved.

The different sections of code involved will trigger different filters.

Comment Moderation

Besides the per blog choice to include comment moderation, the real time per comment choice of the blog owner, is to publish (or not to delete), or to not publish (or to delete) any given comment. This filter leads to the subject of community moderation, and training of the collaborative and heuristic filters, for Blogger hosted comments.

The community moderation filters provide automatic moderation of Blogger hosted comments - and the need for active moderation, by the blog owners.

Google+ Comments

The choice of Blogger hosted comments, vs Google+ hosted comments, provides one more option, to the blog owners.

Blogs which use Google+ hosted comments use community moderation, and free the blog owner to spend more time on blog content. Google+ hosted comments provide real time relation based filters, where the publisher of any comment can designate who will be allowed to view the comment, providing filters which are relevant to the comment publisher.

Cookies and Scripts

Each separate section of code can trigger different script filters - and may require different cookies, which may or may not be present and accessible to the Blogger scripts. Both cookies and scripts are essential parts of Blogger code, which are vulnerable to different security filters at different times.

The mysterious vanishing comments is just one consequence.

Use Of Supported Browsers And Computers

Some people prefer to ignore the crowd, and to use browsers and operating systems that nobody else knows about.

Individuality is good, in general - but in the world of web applications such as Blogger, use of unsupported browsers and computers may bring frustration. Blogger simply can't support all browsers and computers, with equal attention to the oddities presented by each one.

The End Result

The various filters involved cause comments to be published (or not), to remain published (or be deleted), and to be visible when published (or invisible). Many of these details are transparent, to the casual blog reader - until there is a problem.

These details may help to explain the apparent random nature of Blogger blogs and commenting - why comments, posted to some blogs, appear without problem - while comments, posted to other blogs, may never appear, or be invisible.

Saturday, January 14, 2012

Two Level Comments, And One Known Post Template Update

From feedback being received about the recent release of two level commenting, and the many different problems attributed to the release, it appears that there is one commonly identified update to the post template. It's possible that adding this one change, to some blogs with tweaked post templates, may eliminate the need for a post template refresh.

This is a simple change - but it must be made in 4 different places. I highly recommend that you backup the template, before and after making this change. Allow 30 minutes, to concentrate properly on the task.

Installation of this one post template patch may eliminate the need for many people to refresh the post template. It's also possible that this change, done in reverse, may let you disable two level comments, should you wish. In either case, please do this carefully, when you are relaxed, and able to concentrate.
  1. First, backup the template.
  2. Edit the template using the "Edit HTML" wizard, and select "Expand Widget Templates".
  3. Carefully search for each instance of
    <b:include data='post' name='comments'/>
  4. Note that the target snippet (above) is entirely contained in the replace snippet (below). When you identify each snippet found, carefully examine it to make sure that the required code is not already present! Do not replace the target snippet with itself, redundantly!
  5. Replace each instance found, if not already present, with
    <b:if cond='data:post.showThreadedComments'>
    <b:include data='post' name='threaded_comments'/>
    <b:else/>
    <b:include data='post' name='comments'/>
    </b:if>
  6. Save Template.
  7. Clear browser cache, and restart the browser. Test your changes.
  8. Again, backup the template.

Again, I'll advise you to backup the template, before and after doing this.

>> Top

Friday, January 13, 2012

Two Level Comments, And Required Updates To Our Blogs

The new two level commenting feature has been out for a short 2 days - and already there are at least half a dozen separate problems being attributed to the introduction of that feature. Not every blog owner understands how intrusive this new feature must have been, to install, into Blogger.

The previous two Blogger feature releases - dynamic templates, and the New Blogger GUI, required major changes to the Blogger GUI. Two level commenting, while not requiring major GUI changes, was still challenging to develop. Two level comments required a significant upgrade to the content of our blogs, and were activated without the decision of the blog owners involved.

The two immediately previous major Blogger releases - dynamic templates, and the New Blogger GUI, each required a major amount of coding and testing. The bulk of those features, though, involved Blogger GUI code, which was separate from the code in our blogs. Also, both of those features are optional, with various menu selections which allow us to activate, at our convenience - and to deactivate, when we find that either feature is not to our liking.

Two level commenting, on the other hand, was automatically and instantly activated. Owners of almost all blogs which publish a full post feed, and which use the embedded comment form, suddenly found their blogs offering this exciting feature. Installation of this feature was a no brainer - if your blog publishes full posts feeds, and uses the embedded comment form, your blog now has two level commenting.

The automatic activation of the feature, combined with some content and formatting problems attributed to the feature, left some blog owners feeling powerless. People reporting some problems are being told to deactivate the full blog feed, or to change from the embedded comment form, to work around the problems. Neither change is preferred, by some blog owners.

As an alternative to either recommended change, some blog owners may find relief from various problems, by reloading a standard blog template, and / or resetting the post template. For blog owners who enjoyed installing a custom third party template, and tweaking the decorations and layout of the posts, this alternative is even less acceptable than the suggested feature deactivations. Yet if it's productive when tried, this technique should define the base causes of some of the problems being reported.

For blog owners who are comfortable with tweaking the post template, a manual post template update may provide a solution, for some blogs. This manual update, if done in reverse, may allow people to deactivate two level commenting, without deactivating the full post feed, or changing from the embedded comment form.

As Blogger developed and tested the changes required, to make two level comments work, they had the ability to test using the Blogger development environment, and various Blogger provided templates. They had no ability to test using the many blog template custmisations, and post template tweaks, which many of us have installed in our personal blogs. That being the case, many of the observed problems are not entirely the fault of Blogger - we have to accept some responsibility also.

In short, if anybody with a blog that publishes a full post feed, and uses the embedded comment form, finds changes in their blogs which are not to their liking, they need to return their blog and post templates to Blogger standard, before feeling themselves entitled to complain
What did Blogger do, this time?

>> Top

Thursday, January 12, 2012

Two Level Comments And The Comments Time / Date Stamp

Yesterday, Blogger Support delivered one long awaited improvement to our blogs - two level commenting. It was eagerly awaited - and as soon as the Buzz announcement hit the Blogosphere, people were busy checking out the new feature.

Predictably, problem reports have been rolling in, all day today, in Blogger Help Forum: Something Is Broken. One noticed problem report concerns the date / time stamp on the comments.
All of the comments on my blog, even on previous posts, now show an incorrect time. I double-checked my setting, it is correctly set my local time.
The general consensus appears to be that all comments are now posting as Pacific Time (USA), regardless of the blog time zone setting.

This problem, along with several others, has been reported to Blogger Support - and they are now looking into this issue.

Watch this space for updates.

>> Top

Sunday, December 11, 2011

The Comment Notification Option Is Subject To The Realities Of Authentication, And Cookie Filtering

Some blog guests cannot understand why they can't get notifications, when someone leaves a comment after them, attached to a post comment form.
Why don't I see the option to "Email follow-up comments to xxxxxxx@yyyyy.zzz"?
or maybe
I selected the option to "Email follow-up comments to xxxxxxx@yyyyy.zzz", but I don't get any reply notifications. Why am I being mistreated by Blogger?
These people do not realise that comment follow-up notifications are subject to the same problems as the embedded comment form.

Many people, preparing to post a comment on their favourite blog, look forward to reading replies from other blog guests - and become confused when they do not see the option to
Email follow-up comments to xxxxxxx@yyyyy.zzz
They don't realise that they will only see that option when they are logged in using a Blogger account - and when their login status is available to the code behind the comment form. Like the desire to post a comment, using one's Blogger / Google account, this option requires availability of the Blogger login cookie, identifying the commenter as being logged in.

An incorrectly set cookie filter can either prevent availability of the comment notification option, when using the embedded comment form (if "third party cookies" are blocked) - or can prevent availability of the option on any comment form (if cookies, in general, are blocked). In either case, the commenter will be treated, by the comment form code, as not being logged in - and no option will be provided.

Also, if the commenter is successfully logged in, but is not using a Blogger account that's attached to an active email address, he / she can select the notification option, but will never receive a notification. This is a typical problem, with a Blogger account setup using a bogus email address, whether accidentally or intentionally.

So, if you don't see the notification option when you post a comment - or if you select the option but never get any email, don't immediately and unilaterally blame the Blogger commenting feature. Do some research, before reporting your problem.

>> Top

Wednesday, November 9, 2011

Blog Owners Find Static Pages, On Dynamic Templates, Don't Allow Comments

A month ago, we discovered a problem with static pages and commenting, on our blogs. That problem was later fixed.

Yesterday, while exploring a subtle problem with commenting on posts when using a dynamic template, I discovered a new problem with static pages and commenting, also on the dynamic template.

You may examine my static page commenting form, in this blog - and observe that it's possible to leave a comment in that page, Leave Comments Here. Then find the same page, in a dynamic view of this blog, using the link in the menu bar (it's there - move the cursor, slowly) - and again, try to leave a comment in that page.

I think that the above test will illustrate the problem. This problem appears to be distinctly separate from the previously observed problem with the commenting form, and posts, in the dynamic template.

If you design your blog with static pages, and make comments from your readers a significant part of the experience, you may not wish to make the dynamic templates a default view, for your blog.

>> Top

Dynamic Templates And Embedded Comments

We've been observing problems with commenting on blogs using the inline comment form ("Embedded below post"), ever since Blogger changed the inline form, many months ago. First, we observed an overall problem with cookie filtering and the embedded comment form. Later, a more subtle problem with using the CAPTCHA form with embedded comments was discovered.

Now, we're seeing a similar problem, with the new dynamic templates, and the embedded comment form. This problem may not be any more obvious, to some blog readers, than the preceding problems were.

I've been providing advice, in Blogger Help Forum: Something Is Broken, for various blog owners whose readers cannot comment, for some time.

Many problems which involve commenting start with content filters.

Generally, the problem is simply caused by overly optimistic cookie and script filtering. Resolution of the problem may involve changing comment form type, for blogs with certain reader populations.

Dynamic templates appear to present other challenges with commenting.

This week, I tried posting test comments in various blogs that use the dynamic templates, as a default view. There are several possible challenges here.

  • Main page view may not inform the casual reader that comments are permitted.
  • Local rendering of blog content may be a problem, on some computers.
  • The mechanics of the dynamic template post overlay may cause confusion.
  • Different dynamic views may provide more or less of a challenge.

Main page view may not inform the casual reader that comments are permitted.

Main page view, in the dynamic template, may confuse the reader. Main page view, for blogs not using the dynamic templates, will provide a link below each post, "nn Comments" ("nn" stating the current comment count).

With the reader clicking on the link, the individual post page will be presented, with the browser positioned at the top of the embedded form below the post. The reader will not be immediately aware of the display change - but may simply see the comment form, displayed before his eyes.

The dynamic template equivalent of main page view will show just a snippet of the post, or the complete post - but with no mention of Comments, anywhere. To have any chance of posting a comment, the reader must know to click on the post, and view the post in the overlay.

With the individual post visible in the overlay, the reader must know to scroll to the very bottom of the overlay. With the design of the single post overlay, this involves explicitly scrolling to the very bottom of the screen - again, not an obvious procedure. At the very bottom, one will find the simple caption.

Add a comment

Clicking on the caption, and / or scrolling again, the reader finds the embedded comment form.

With the Classic Dynamic View selected (either by the blog owner, or by the reader), there is no overlay used. Even so, there is another possibility for confusion.

When there are no comments published to a given post, one will see the link "0 comments" or "Add a comment". Clicking on the link, one will scroll to the very top of the comment form.

Depending upon the size of the display, the bulk of the comment form will remain invisible - and again, the need to scroll just a bit farther won't be immediately apparent - and the would be commenter will again go away, in confusion.

Local rendering of blog content may be a problem, on some computers.

Since the dynamic template is being rendered in real time by the readers computer, each display may not refresh, immediately. If the readers computer is busy, or low on resources, the display may not be immediately updated.

There is no indicator in the dynamic view, that indicates to the reader that the display has a pending update. The reader may not observe the delay - and may casually think that there is no comment form available for the page or post.

After entering the comment into the box, selecting the appropriate authentication, and hitting the "Post Comment" button, the reader will be presented with the CAPTCHA form. Options for the second and third steps will vary, at the pleasure of the blog owner.

Again, depending upon how busy the computer is, the CAPTCHA form may be presented immediately - or may require that the reader again scroll to the bottom.

The mechanics of the dynamic template post overlay may cause confusion.

Finally, after the CAPTCHA (when required) is successfully solved, and if comment moderation is being used, the reader is shown the well known (and not always observed) advice

Your comment will be visible after approval.

If, during any of the above steps, the readers computer not rendering the next display promptly, the reader may become confused and close the overlay. The next step will involve the reader communicating with the blog owner (when the owner is fortunate enough).

I wanted to leave you a comment, but your blog doesn't accept comments. What the &*^^% are you doing with the blog, this month?

Different dynamic views may provide more or less of a challenge.

These effects may be more obvious with views that display the complete post in an overlay, and with longer posts.

The Classic and Sidebar views display the complete posts in a more conventional style - and the comment form is more visible. With shorter posts, that fit within the browser window, the comment form is more visible.

Look at one post, from my Musings blog.


My blog, with a short post, displayed using Standard view.




My blog, with a short post, displayed using Classic view.




My blog, with a slightly longer post.



Not all dynamic views will present the "Add a comment" link, as easily displayed for the readers, for all posts on all blogs.

And once again, we have another issue for Blogger Help Forum: Something Is Broken.

My readers cannot comment on my blog!

And, another mystery will fill the forums.



Owners of some #Blogger blogs may observe that reader commenting is not as active, having recently published to a dynamic template. There are a variety of reasons for the change in activity.

Tuesday, October 18, 2011

Blog Owners Find Static Pages Don't Allow Comments

Last week, blog owners discovered a new problem with commenting on their blogs.
I keep enabling comments on my pages, but Blogger keeps disabling them!

From having observed the reports of the problem, it appears to affect all blogs - both varying template type, and use of the different GUIs (Classic and New 2011), appear to be referenced.

Blogger Support has acknowledged the problem.
Thanks everyone for your patience, we're hoping to have a fix rolled out shortly.

(Update 10/19): This has been corrected.

(Update 11/09): Today, we see a new problem with static pages and comments - this one involving dynamic views.

>> Top

Navigate» Become author for this Blog