Showing posts with label Comments. Show all posts
Showing posts with label Comments. Show all posts

Tuesday, January 24, 2017

Comment Publishing Preview, And "Error 400"

We're seeing a problem with Blogger Hosted Comments - and "Bad Request Error 400", following the use of the comment "Preview" feature.

When a blog owner or reader composes a long or important comment, use of the Preview feature is normal. Right now, after hitting "Publish", following a successful Preview, one frequently sees the bad news.
Bad Request
Error 400
There is a workaround for this annoyance - and it's not difficult to use.

Until Blogger Engineers fix the "Error 400" problem, there is a workaround - and the workaround adds very little time to comment publishing.

The most obvious alternative would be to not use Preview. But how well can you eyeball your comment, without Preview?

If you find it inconvenient to eyeball check a comment without using Preview, it's a small effort to copy then paste, before Publishing. Just a little planning, before composing, lets you copy then paste.


OMG, where is my comment? All my work, gone??



Opening a new tab / window lets you publish, after the preview / edit cycles (and avoid the "Error 400"), when composing an important or long comment.


Here's the key to the workaround. "Open link in new tab" - a context menu option, for any link.

With most browsers, you'll either "Alt" click or right click on the link, to get the context menu.



  1. Recover the comment content, if you're looking at the "Error 400".
  2. Open the post, where a comment is needed.
  3. Open a comment composition window, in a new tab / window.
  4. Compose the comment, carefully edited.
  5. When satisfied by the Preview display, click Edit once more.
  6. Copy the edited comment.
  7. Close that browser tab / window.
  8. Open a comment composition window, again.
  9. Immediately paste into the new comment composition window.
  10. Immediately Publish.
  11. Done.

Recover the comment content, if you're looking at the "Error 400".

If you're looking at the "Error 400" display, right now, refresh the display and follow the prompts. Recover the comment composition window, with your work in progress. Skip ahead, to Step #6.

Open the post, where a comment is needed.

Start with a post - and the "Post a Comment" link at the bottom of the post.

Open a comment composition window, in a new tab / window.

Click on the "Post a Comment" link - and use the "Open in new tab / window" browser option. With most browsers, you'll either "Alt" click or right click on the link, to get the context menu - and the "Open in new tab" / "Open in new window" option.

Compose the comment, carefully edited.

Use Preview and Edit, and the composition window, as necessary. Compose, preview, and edit - until your comment is properly phrased.

When satisfied by the Preview display, click Edit once more.

If it's an important or long comment, you'll use the Preview - Edit sequence, a few times. Just finish, with a final "Edit".

Copy the edited comment.

From the comment composition window, hit "Ctrl - A" to select everything as edited, then "Ctrl - C" to copy.

Close that browser tab / window.

Close the tab / window - and bid farewell to the carefully written content, and the Bad Request.

Open a comment composition window, again.

Click on "Post a Comment" from the displayed post - again, using "New tab / window". You will have an empty comment composition window.

Immediately paste into the new comment composition window.

Immediately paste the copied comment ("Ctrl - V") into the empty comment composition window.

Immediately Publish.

You already previewed and edited your comment - now, Publish.

Done.

The comment publishes - and, you're done.

Do this a few times - you'll see that this adds maybe 30 seconds to the comment composition / preview / edit cycle.

How long does it take to compose (preview, edit) a comment, to your liking? I take a lot longer than 30 seconds.

Just copy, close, open, paste, and publish.

And you're done.



Publishing a comment, using #Blogger hosted comments, following use of the Preview feature, subjects us to "Bad Request Error 400". Using a browser supplied new tab / window, and copying then pasting, we can workaround the "Error 400".

Thursday, June 9, 2016

Inaccessible Comments, On Some Popular Posts

Viewing comments, on some popular blogs, one may get the idea that not as many comments are being published, as are immediately visible.

With a large comment complement, comments are paginated - with some comments hidden behind a link, captioned "Load more". The "Load more" link is JavaScript based - and there is a problem.

The "Load more" link does not always work, on all blogs.

Comments on some blogs may be unreadable - with the "Load more" link not operational.


Some posts never display all comments.




Look at the bottom of the page, below the post.




And there is the "Load more" link.




And the link, as seen when one mouse over it, is shown to be JavaScript based.




And clicking on the link yields the caption "Loading ...".




And "Loading ..." never goes away - and we get no view of the missing comments.



I've seen this problem with blogs using both dynamic and non dynamic templates.

Both dynamic templates, and non dynamic templates, appear to use comments paginated behind "Load more" - and may exhibit this problem. I've seen this problem, reported in Blogger Help Forum: Get Help with an Issue, for both template types.

I have reproduced this problem, using two blogs.

Here are two recently reported cases, reproduced in my testing today. I do not know how long both cases may be active.

http://slifkinchallenge.blogspot.com/2016/05/thank-you-yehoshua-duker-and-yosef.html
https://productforums.google.com/d/topic/blogger/RotUfv8AwuU/discussion

http://istanbulkonstantinopel.blogspot.com/2014/03/study-in-turkey-2.html
https://productforums.google.com/d/topic/blogger/7Yau3KKR9mo/discussion


Noting that both blogs are (natively) published in countries that are subject to local country codes (Israel and Turkey, respectively), I will deny that to be a simple affinity - since I viewed both blogs from my browser, as "blogspot.com", as I reproduced the problem. That said, that is an interesting coincidence, no?

There are several possible causes of this problem. Adding the above observation, some of these causes may be more or less relevant.

  • Comments feed setting.
  • Comment feed content / corruption.
  • Cookie / script filters.
  • HTTPS Redirect.
  • Occam's Razor.
  • Post template corruption.

Comments feed setting.

Features like the comment reply option, and blogs published to dynamic templates, require a full comment feed. It's possible that comment pagination, behind JavaScript links, is similarly sensitive to the comments feed setting.

This detail will affect everybody - both blog owner(s) and reader(s) alike. And it will probably affect all posts, uniformly.

The solution for this problem would involve checking - and correcting - the comments and feed settings, for the blogs involved.

Comment feed content / corruption.

Similar to the problem with the Blogger blog post published location, it's possible that some unknown detail in the data could interfere with script functionality.

If the problem involves content in one post - or a comment on one post, it's possible that comments for one post could be affected; but other posts could paginate comments successfully.

This detail would probably affect everybody, uniformly.

The solution for this problem will require determining what feed content detail causes the problem. This will probably involve affinity diagnosis.

Cookie / script filters.

Any problem which involves a JavaScript based link, both cookies and scripts are always going to be involved. Any filter that interferes with either cookies (identity) or scripts (link functionality) will always be a possibility.

Filters may affect either blog owners and / or blog readers, uniquely. A problem that involves some owners / readers will likely involve filters.

Thanks to the effect of country local domains, cookie / script filters may affect individuals geographically.

The solution for this problem is to check / open up script filters - and then check / open up cookie filters.

HTTPS Redirect.

Both blogs, identified above, appear to not be using the "HTTPS Redirect" option. It's not impossible that this is another feature, broken by the SSL Rollout.

Occam's Razor.

Considering the most simple alternative, is it possible that paginated comments are simply inoperative? Maybe, because of (or incidentally involving) the SSL Rollout??

Post template corruption.

Comments are part of the post template. It's likely that proper comment functionality also requires a clean post template. This detail will probably affect everybody - though it's possible that there could be code that is sensitive to some owners / readers, but not others.

The solution for this problem is to reset the post template, on the blogs involved.

The bottom line.

This problem, if not incidentally solved by a Blogger code change, will probably not be diagnosed, immediately.

More examples of this symptom are badly needed. Right now, we have seen only a handful of people with blogs that are popular - and generate comments in sufficient volume - and have reported this problem.



Some #Blogger blog owners, who publish blogs with posts that receive large volumes of comments, report inability to display all comments published. Comments, when displayed in large volumes, are paginated behind JavaScript based links - and some links, when clicked, don't seem to work.

https://productforums.google.com/d/topic/blogger/7Yau3KKR9mo/discussion
https://productforums.google.com/d/topic/blogger/RotUfv8AwuU/discussion

Monday, May 30, 2016

Microsoft Windows Security Updates, May 2016

If you use a computer that runs Microsoft Windows, you may have been affected by Microsoft supplied updates, distributed 3 weeks ago.

May 10 was the day termed "Patch Tuesday" - the day when Microsoft releases important security related patches, to its various Internet updated products. During the 3 weeks after May 10, we've seen a significant number of security related discussions, in Blogger Help Forum: Get Help with an Issue.

It appears that Microsoft updates, for May 2016, affect use of Blogger.

The Microsoft Security updates, applied May 2016, appear to have affected various Blogger features, that are known to be vulnerable to layered security.

  • CAPTCHA visibility when daily post limit is exceeded.
  • Publishing comments, or replying to published comments.
  • Quick Edit icons.
  • Followers / Reading List maintenance.
  • Stats self initiated pageviews.

All of these features are known to be affected by cookie filters, and / or by script filters.

If you are using a computer that runs either Microsoft Windows 7 or Windows 10, and you are experiencing a problem with publishing comments, or with using Quick Edit, or with blocking your own views in Stats, or similar problems, you may want to check your cookie and script filters.

I note that some of the reports mention the browser used as Chrome or Firefox. You'll want to check filter settings in Windows Security Essentials.

Being realistic, it's also possible that Microsoft broke something within Windows - but we'll have to wait patiently, for them to admit that.

If you need different or more advice, please start a new topic in Blogger Help Forum: Get Help with an Issue.



Microsoft released monthly security updates May 10, 2016 - and since that date, there have been a number of security filter related issues, reported in Blogger Help Forum. It appears that the the Microsoft Updates involve cookie or script filters, which affect use of Blogger.


Tuesday, May 24, 2016

Blogger Magic - Comment Moderation Settings

If you publish a blog, and want your readers to comment, you need to decide whether to moderate comments.

Comment moderation, applied properly, help you to keep abusive and spam comments off your blog. If you want to publish a blog, and have real people commenting, you need to keep spam comments off the blog. People won't comment, if they have to compete with spam.

If you want to publish a blog, and allow Blogger Hosted comments, you really should moderate. If you don't moderate, prepare to remove spam comments after they are published. Remember that Google+ Hosted comments are moderated by the community.

You setup moderation, for Blogger Hosted comments, from the dashboard Settings - "Posts, comments and sharing" page.

Under "Comments", you have "Comment Moderation", with 3 settings.

  • Always.
  • Sometimes.
  • Never.


Moderation settings are in the Settings - Posts, comments and sharing page.



Moderate Always.

Every comment, published by somebody who is not an administrator or author, will be moderated.

With "Always" or "Sometimes" selected, moderated comments will be sent to each email address listed in "Email moderation requests to".


Select "Always", "Sometimes", or "Never".



You - or whoever is addressed under "Email moderation requests to" - will have the ability to moderate from the email message received. You, or any blog administrator, can moderate from the dashboard Comments - "Awaiting moderation" page.

Moderate Sometimes.

You can selectively moderate comments for older posts, with newer posts not subject to moderation.


If you select "Sometimes", you provide a moderation threshold.




Here, we are set to moderate all posts older than 14 days.



Every post subject to moderation will receive the treatment, selected for "Always". Every newer post, not subject to moderation, will permit any comment to be published immediately.

Moderate Never.

Any comment, submitted to be published, will publish immediately.

Dashboard moderation offers three options.

With every comment listed in the dashboard Comments - "Awaiting moderation" page, you have 3 options.

  • Publish.
  • Delete.
  • Spam.

Once one of these options is chosen, for any comment being moderated, you'll have similar - but not symmetrical - options.

EMail moderation offers similar options.

With each comment moderated by email, you'll have 3 similar options.

  • Publish.
  • Delete.
  • Mark as spam.


Select "Publish", "Delete", or "Mark as spam".



Besides moderation, you can select CAPTCHA verification.

Besides moderation, you can reduce spam, using CAPTCHA verification. If selected, all non administrators and authors will be subject to CAPTCHA verification.

If not selected, anybody commenting anonymously - and not signed in with a Google account - will still be subject to CAPTCHA verification. The "Show word verification" setting applies to comments posted with the publisher properly authenticated.

Right now, the CAPTCHA used is a word puzzle - and has received mixed reviews.

The bottom line.

As a blog owner, you should choose a comment moderation policy - if you allow Blogger Hosted comments.



If you allow #Blogger Hosted comments on your blog, you need to choose a moderation policy. Moderation is essential, to reduce spam, and encourage comments by actual blog readers.

Wednesday, March 30, 2016

Using A Killfile, To Filter Blogger Comments

We periodically see hopeful - yet naive - requests from blog owners, in Blogger Help Forum: Learn More About Blogger, asking about comment moderation improvement.

How do I add a disruptive commenter to a killfile list - and never see his/her nonsense ever again, without moderating every comment, being published?

This would be a popular feature - if it could be provided, in any way that would achieve results.

Using a killfile, to filter disruptive / malicios commenters, is not a likely possibility.

Anybody who does not want to be identified can comment as desired.

It is not possible to reliabily identify a comment publisher, who does not wish to be identified.

  • Blogger / Google identity.
  • IP address.

Disruptive individuals can't be identified, with any chance of success. Anybody who wants to publish comments can do so, using multiple accounts, and / or IP addresses.

Both Blogger / Google accounts and IP addresses can be easily cloaked.

Using either multiple Blogger / Google accounts - or IP addresses - is a trivial exercise for anybody who is determined enough to persistently publish unwanted comments.

Given the impossibility of identifying people who don't provide effective identification, Blogger is unlikely to provide a feature that would accomplish nothing - and possibly interfere with legitimate commenting.

The only solution for blocking unacceptable comments will always involve collaborative, fuzzy filters, trained by each blog owner.



Some #Blogger blog owners would like to use a killfile, to filter unacceptable comments. They don't understand that anybody who wants to persistently publish disruptive or malicious comments can easily mask their identity - and make killfile use an exercis in futility.



Friday, March 18, 2016

Commenting Requires Login, To Suppress Spam

Some blog owners don't understand the need to identify themselves, when commenting on our blogs.

We see an occasional question, in Blogger Help Forum: Get Help with an Issue, about comment authentication.
Why, if I've selected "Anyone - including Anonymous Users" under comment settings, for "Who can Comment?", do my visitors complain of having to login?
This blog owner, like many others, does not understand the Blogger spam mitigation policy, in Blogger Comments.

Blogger lets us select who we wish to allow to comment, on our blogs.

When we do not moderate, they require authentication, to cut down on the spam. Moderated comments, with CAPTCHA ("Show word verification") not required by the owner, appear to go straight to moderation.

Comment authentication makes genuine comments more normal.

By requiring authentication, Blogger makes it more likely that a comment, awaiting moderation, will be genuine - instead of more spam. This encourages us to moderate comments more frequently - and helps us publish moderated comments, more promptly.

And more frequent moderation discourages spam - and makes it more likely that we will see actual comments, later.

Blog owners choose how to allow comments.

As a blog owner, it's your choice how / whether to allow comments.





  • Anyone - includes Anonymous Users.
  • Everybody with a Google, or an OpenID, account.
  • Everybody with a Google account.
  • Blog members only.
  • Comments disabled.

Blog readers choose how to publish comments.

Depending upon the choices that you provide, your readers choose how they may authenticate.

  • "Anyone" allows a reader to comment anonymously - or identified.
  • If they wish to comment anonymously, they login, using a CAPTCHA.
  • If they wish to comment using a profile, they login, using an account.
  • Login is generally only required, with the first comment.

"Anyone" allows a reader to comment anonymously - or identified.

"Anyone" allows anyone to comment anonymously (if they wish). To cut down on spam, anyone commenting has to login.

If they wish to comment anonymously, they login, using a CAPTCHA.

Solving a CAPTCHA lets them remain anonymous - but still identify themselves as a person, not a bot. Any comments, awaiting moderation, or published, are more likely to be genuine - not spam.

If they wish to comment using a profile, they login, using an account.

They can login, as permitted, using a Google or OpenID account. Anyone able to login with a Google or OpenID account can still publish a comment anonymously, if they wish.

Login is generally only required, with the first comment.

If someone has to login repeatedly, to comment, they have a problem with identification, and filters. With cookies and scripts properly permitted, login (with the first comment) will be remembered (with any later comments).

The Blogger / Google login status, and the ability to post comments, is sensitive to both cookie and script filters. Your readers may need to enable (stop filtering) "third party cookies", in their browser and on their computer - if they wish to comment, most easily.



Both a #Blogger blog owner - and blog readers - get choices how to authenticate when commenting. Depending upon the choices made by the owner, the readers get more, or less, choices.

Friday, February 26, 2016

Comments "Lost", With Google+ Comments Selection

Besides the confusion about being in the right Circles, some Google+ comments can be overlooked, because of the comment view selector.

We see odd problem reports, in Blogger Help Forum: Get Help with an Issue.
When a friend mentioned she'd commented, I found that odd - because I couldn't find the comment anymore. It had shown up previously - but it was now gone.
The view selector is not so obvious, either. It's similar to the "Compose" / "HTML" buttons, in Post Editor.

Besides the view selector, we see another possibility for third party cookies, unwisely filtered, to cause confusion.

Displaying comments for a blog, with Google+ comments involved, requires determining the identity of the individual viewer. Viewer identity - much more specific than "blog owner" / "blog guest" - is required, to determine visibility of specific comments, published against a given blog.

Here's an example, using a post from my recipes blog.


12 comments - from Circles + Public.




Circles + Public, selected.




6 comments - from my Circles.




Circles only, selected.



Can you see the difference? Other viewers of the blog will see a completely different set of comments.

Here's a different example, from a forum topic.


The blog owner, signed in, sees a count of 27 comments.




The blog owner, not signed in, sees a count of 42 comments.



There's actually 3 possible different displays - each showing a different comment count, and a different list of comments.

  1. Not signed in.
  2. Signed in, looking at "Public" + "Circles".
  3. Signed in, looking at "Circles" only.

One might expect #1 and #2 to be the same. In some cases, it appears that #1 displays a total comments count - though #2 and #3 display a count specific to the blog owner or reader. And I would not expect that one will actually see a precisely equal number of individual comments, displayed.

And if blog owner / reader access is affected by a third party cookie filter, both the comment count - and the list of comments displayed - will be smaller than what really should be displayed.

We now have a Rollup Discussion, in Blogger Help Forum: Get Help with an Issue, where we are requesting details from anybody experiencing mysterious loss of comments, If you are losing comments, please provide your details.



Owners of #Blogger blogs that use Google+ Comments don't realise how much more important their personal identity is, when looking for comments, that should be displayed with the individual posts. Personal identity is further relevant, with the "Circles" / "Public" comment selector, a feature of Google+ Comments.

And determining personal identity is affected, when cookie filtering becomes involved.

Wednesday, January 21, 2015

Google+ Comments Are Open To Everybody

One source of occasional confusion, seen in Blogger Help Forum: Get Help with an Issue, is about Google+ and the lack of control.

We have discussed the lack of commenting moderation options - but that's just a small part of what you don't get.
Under Settings, then Posts and comments, I don't have the same choices as shown.
This blog owner is used to the array of comment settings, that seem natural, to somebody using Blogger comments.

With Google+ comments, you get one setting, under "Posts and comments" - Comments.

Comment Location

Everything else is part of Google+, and stream behaviour.

Anybody who can see the blog can publish a comment.

Besides the lack of moderation options, the lack of control over who can comment can be disconcerting. With Google+ Comments, anybody, who has an Exciting Google+ account, can comment - just as in the Google+ stream, anybody can post anything they wish.

Unless you, the blog owner, are in a Circle that's addressed by a commenter, you won't even see a non Public comment - even if your blog is mentioned. This leads to more confusion.

Why does the comment count go up for this post - even with no comments visible?

Google+ will count comments that you may not get to see. This too can be disconcerting. Anybody can comment, on your blog - and you can't see the comments. Comment moderation is left to the people who can see the comments.

Google+ Comments only work for public blogs.

But there's a more intriguing oddity. We are told to use Google+ for distribution of private blog posts - but you cannot use Google+ Comments on a private blog.

Google+ hosted comments only work, with public blogs. With a private blog, you use Google+ to distribute the posts - but you can only use Blogger hosted comments.

Since automatic post sharing only works for Public shares, you have to manually share each post - so you can select the appropriate Circles to view each individual post.

If you have a private blog, your readers can discuss your blog posts, in their streams - but nothing will show up on the blog. And, they can view the blog - and possibly comment there - but nothing will show up in their streams.

Monday, January 5, 2015

Inviting Comments To Your Blog Is Not Cut And Dried

Blog owners are periodically asking themselves
How do I invite my readers to leave comments?
Some blog owners think of commenting as the most important way to get new readers.

One of the most seemingly insignificant components of the Blogger template is the link to invite the readers to leave comments. This is not a simple feature - it varies according to where the comment form is placed, and to different language and style decisions.

Variations
There are four comment form placement options, for Blogger blogs.
  1. Embedded.
  2. Full page.
  3. Pop up window.
  4. Dynamic template.
There are two display contexts.
  1. Index page view (archive retrieval, label search, main page).
  2. Post page view.
Some blog owners may confuse index page view, with "Show at most" set to "1 Post", to post page view. This won't be the case. "Show at most" will only apply to main page view. And main page display with only one post displayed, without jump break, will still be index page view.

Some blog owners may confuse index page view, with "Show at most" set to "1 Post", to post page view. This won't be the case. "Show at most" will only apply to main page view. And main page display with only one post displayed, without jump break, will still be index page view.

The placement option, added to the display context, creates a combination of various needs for phrasing the simple caption, which I will call for example
Please, leave a comment!
That simple invitation can vary according to the the nationality of the blog owner, and to the nature of the blog.

Blog Language
Comments is an English word. Every blog that's published in a non English language has a different word for "comments".
  • en français: commentaires.
  • in italiano: commenti.
  • en español: comentarios.
And some languages phrase plurals significantly.
  • 0 comments.
  • 1 comment.
  • 2 comments.
Very few blog owners publish a blog in (USA) English, and want the blog captioned with "1 comments", or "2 comment".

Long ago, somebody decided that inviting comments would be easier, if a blog with 0 comments was captioned with "No comments". Then, another grammar expert (lawyer?) decided that "No comments" could be interpreted by some people as "We don't want comments!".

Blog Nature
Then, some blog owners don't like the word "comments", they feel that the word should be changed, to reflect the nature of their blog. For my blog, "Chucks Musings", I would use "musings", instead of "comments" (but with dynamic templates, that option is not yet available). Other blog owners have used "dreams", "introspections", and "wanderings" (to name a few).

Form Placement
One of the most controversial features of comments is the limitation of displaying the individual comments, and the comment form, only beneath the individual posts. On the main page, for all comment placement options, you will see the comment caption "No comments", "1 comment", etc - which then links to the display of existing comments - and to the form to publish a comment.

All existing placement options now display existing comments only beneath the individual posts. With the full page and popup window options, a link captioned "Post a Comment" then leads to the comment form itself.

With the full page and popup window form, for the convenience of the owner and reader, existing comments are displayed there also. And, wherever the comment form is displayed, so must be the hated CAPTCHA form.

The Reader's Language
To further the confusion, some blog features are automatically translated into the readers language - when the reader is logged in to Blogger / Google, and when the reader's login status and Blogger profile can be determined by the blog display. In some cases, the readers location is used.

Sometimes, both the blog owner and reader could read / speak different languages, neither being English. Not every world citizen understands "Please, leave a comment!" - or even "Post a Comment". And some blogs are published in French - and read in both Italian and Spanish.

The Tower Of Babel
The Tower Of Babel is not going away, in this lifetime.

Thursday, December 11, 2014

Confusion From Comments And The CAPTCHA

This week, we're seeing complaints from quite a few angry blog owners, in Blogger Help Forum: Get Help with an Issue.
Why do I have to solve a CAPTCHA, to comment on my own blog?
and
Everybody sees a CAPTCHA - even if they are logged in to Blogger!
Previously, the CAPTCHA was visible only to those not logged in to Blogger, or to those wishing to comment, anonymously.

It appears that the full page and popup window comment forms were updated, possibly to make the CAPTCHA form more usable, for those blog readers who are using a computer subject to filtering of "third party" cookies.

The CAPTCHA appears to be always required.

The effect that we are now seeing is that the CAPTCHA appears to be required, for all comments, when the full page and popup window forms are used.

In some cases, even with the CAPTCHA displayed, you can publish without solving.

  • If you are authenticated, the reCAPTCHA, though displayed, may not require solution.
  • If you are authenticated, and a blog member, neither the ezCAPTCHA nor the reCAPTCHA should require solution.

In either case, simply compose and Publish your comment.

People who wish to publish anonymously will always have to solve a CAPTCHA.

Unfortunately, people who are publishing anonymously will still need to solve the CAPTCHA. The non optional reCAPTCHA, which gets displayed, is not as easy to solve as the optional ezCAPTCHA.

Cookie filtering, once again, may be part of the problem.

To increase the confusion, people using a computer where "third party" cookies are filtered will be treated as if they are publishing anonymously, and will have to solve the reCAPTCHA. Some people, who think that they are properly authenticated, will find out otherwise, if they try to publish a comment without solving the CAPTCHA.

Continuing to cause confusion, in some cases, comments entered may simply vanish, if the CAPTCHA can't be displayed when necessary. This, is another consequence of cookie filtering.

Friday, November 28, 2014

Blogger Blog Readers Unable To Comment, Using OpenID Accounts Hosted By WordPress

We're seeing a scattered collection of reports, mentioning problems publishing comments, using OpenID authentication.

This problem appears to be related to the Blogger rollout of SSL support, for our blogs, which is currently in progress. SSL, or Secure Socket Layer, represents the next step in blog / website security - a step which the Internet community has been taking, for many years.

Blogger has been using SSL (aka "HTTPS" login), in their dashboard, for several years.
https://www.blogger.com
That's a secure Blogger login. The problem with Blogger using SSL in our blogs is that moving to SSL requires care, to avoid confusing our readers. Lack of care will subject our readers to the well known "mixed mode" warnings.
This site has insecure content.
Only secure content is displayed.
Firefox has blocked content that isn't secure.
These are several examples of what were normal, years ago, on many websites. Blogger does not want our readers subject to needless confusion, from these warnings.

Blogger blog owners have been asking, for years, that Blogger support SSL in BlogSpot (and our custom domains).

FaceBook upgraded to SSL, in 2013 - and saw problems with Blogger content.

Last year, FaceBook upgraded to SSL. Blogger blog owners, who were also FaceBook members, watched their Walls, which contained HTTP links to their Blogger blogs, show the "mixed mode" warnings.
The real issues begin to arise, however, when your application must include assets served by servers which also do not support SSL.
...
We’ve all experienced “mixed mode” warnings, with some browsers being much more annoying about them than others. "Mixed mode" means you requested a page over SSL, but some of the resources needed to fully render that page are only available over unencrypted HTTP.

Blogger is offering the option for us to upgrade our blogs, this year.

Now, Blogger is upgrading, so our blogs may (optionally) support the SSL protocol - and not confuse FaceBook members, who post links to our blogs. To avoid the "mixed mode" warnings, which would confuse our readers, they are upgrading all Blogger processes, including OpenID authentication, to support SSL.

The Blogger upgrade has exposed a WordPress inconsistency.

Just as FaceBook upgrading to SSL helped to cause Blogger to upgrade, so is Blogger upgrading to SSL exposing an inconsistency in WordPress use of SSL, for OpenID authentication.
The problem in my case (and maybe in others as well) seems to be that https://yourblog.wordpress.com is send for verification to the OpenId server. This is what I could figure out from the URL. If you than manually replace HTTPS with HTTP, it works.
This comment suggests that WordPress, which in general is using SSL security, has an OpenID server that has not been upgraded.

WordPress needs to check their OpenID servers.

So now, Blogger has to wait for WordPress to fall into step, consistently. Until WordPress upgrades their OpenID server, people who want to use a WordPress OpenID account, to comment on our blogs, will have to select "OpenID", instead of "WordPress" - then enter the WordPress OpenID URL, as
HTTP://whatever.wordpress.com
And wait for WordPress to upgrade their server.

Monday, November 24, 2014

Use A Blogger Blog As An OpenID Host

We see an occasional request, in Blogger Help Forum: Learn More About Blogger, about commenting and the profile used when authenticated.
How do I have my comments linked directly to my blog? I don't want my comments linked to my profile, with people having to hunt for my blog links!
This person does not understand why we have Bogger / Google / Google+ profiles, linked from our comments.

Even if we can't provide direct links to our blogs, when commenting using a Blogger or Google account - we can do that, if we can comment, using an OpenID account. An OpenID account links directly to our designated blog - when we specify the right blog URL, while logged in using OpenID, to publish a comment.

Your Blogger blog will provide an OpenID account, just as well as a FaceBook or WordPress account will do, for any Blogger blog using Blogger hosted commenting. Blogs using third party commenting systems may, or may not, support OpenID.

Blogger has been providing, OpenID authentication, for comments, for some time.

Getting OpenID to work - to allow comments using a Blogger based OpenID "account", is not automatic, however. The OpenID V1 tags, which are part of the standard Blogger blog header, don't work. You'll need to replace them, with OpenID V2 - and you will need a Blogger account, with a Google / Google+ profile.

Here, as always, I'll advise you to backup the template - before and after tweaking it.

You'll add 3 lines of code. Copy and paste 3 lines (which may display here as up to 6 lines, wrapped), below.
<link href='https://www.google.com/accounts/o8/ud?source=profiles' rel='openid2.provider'/>
<link href='http://www.google.com/profiles/nnnnnnnnnnnnnnnnnnnnn' rel='openid2.local_id'/>
<link href='http://www.blogger.com/openid-server.g' rel='openid.server'/>


Access the dashboard Template wizard, and use "Edit HTML". At the top of the header section, look for the "all-head-content" tag.

Change
<b:include data='blog' name='all-head-content'/>
<title><data:blog.pageTitle/></title>
To
<b:include data='blog' name='all-head-content'/>
<link href='https://www.google.com/accounts/o8/ud?source=profiles' rel='openid2.provider'/>
<link href='http://www.google.com/profiles/nnnnnnnnnnnnnnnnnnnnn' rel='openid2.local_id'/>
<link href='http://www.blogger.com/openid-server.g' rel='openid.server'/>
<title><data:blog.pageTitle/></title>
Then, replace
nnnnnnnnnnnnnnnnnnnnn
with your Google or Google+ profile id. And hit "Save template".

The next time you are preparing to comment, on a blog that supports OpenID based comments, select OpenID, and provide the URL of your blog.

You will have to login, using your Blogger account with the right Google / Google+ profile, and accept the comment. Other than that, it's pretty straightforward.

>> Top

Sunday, November 23, 2014

Change Per Post Comment Settings, One Post At A Time

Occasionally, we have a blog owner trying to enable commenting, on a blog - and being unsuccessful diagnosing commenting problems.

Checking the per blog comment settings, in the the dashboard menu under Settings - Posts and comments, there's no obvious problem. The problem, in some cases, is in the per post settings, in the Post Editor "Post settings - Options" wizard - but not all posts will have a problem.

The "Reader comments" setting, for any new post, is taken from the setting for the previously published post. If you publish a post today, with "Reader comments" selected as "Don't allow", the next post will also be set to "Don't allow" - unless you change the setting, before publishing. Similarly, if it's set to "Allow", the next post published will have it set to "Allow".
  • Allow
  • Don't allow
That's the choices, for each new post.

If the setting for any post is wrong, according to your policy, it's up to you to change the setting, for that post.

Since the per post setting overrides the per blog setting, any existing posts, with the setting "Don't allow", will not allow comments. To change this, you have to edit each post, one by one, and change the setting.

If the setting is "Allow", and you want to disable comments, you have to change the per post setting, one post at a time. Again, any new posts will then have the setting "Don't allow" - but any existing posts will have to be changed, one post at a time.





If you occasionally disable comments, check this setting before you publish a new post - and make sure that comments are enabled, when appropriate.



If you backdate a post, and publish it before any previously published posts, the setting for the previously published posts won't change. If this creates a range of posts, with inconsistent settings - some allowing comments, the others not allowing comments - you'll still have to change the setting as you wish, for each post, one by one.

If the setting for a post is currently "Allow", and a post has comments, you'll have 3 options for that post.
  • Allow
  • Don't allow, show existing
  • Don't allow, hide existing
That's the choices, for each post with comments.

If you're in the habit of changing the comment setting for various posts, you'll want to check the setting, for each new post - and make sure that it's appropriate. Better that, then to have to change a whole bunch of posts, one by one, later.

Tuesday, November 18, 2014

Comments, Owner Choices, And Reader Choices

Much of what we do in life - and what we do when using Blogger - is based upon, and limited by, choice.

Some choices we get to make, for ourselves. Other choices are made for us, by people who make their own choices.

Some blog owners do not want their readers to have to login to Blogger, to comment on their blogs. Other blog owners do not want their readers to have to solve a CAPTCHA, to comment on their blogs.

A few blog owners do not want their readers to have to do either.
It seems anyone who wishes to leave a comment, will have to do some form of login, either via Google or a CAPTCHA, to do so! Is there a reason for this, would it not be easier, for anyone to just leave a comment?
And the answer here is simple.
It would be easier, if neither were required.
But reality - involving activity by spammers, and activity to counter spammers - leaves some of us with less choices.

Long ago, Blogger allowed anonymous comments, without a CAPTCHA to solve. Spammers benefited from that possibility.

Later, Blogger added the ezCAPTCHA, to be required at the owners decision. Some owners chose to not select the CAPTCHA, because their readers were inconvenienced. Spammers continued to benefit from blogs which allowed anonymous comments, and no CAPTCHA.

Recently, Blogger added the non optional reCAPTCHA. This requires anybody not logged in to have the choice - login, or solve a CAPTCHA.

Unfortunately, the latter change made the third party cookie filter issue more critical. People who are already logged in, but are subject to third party cookie filtering, have to login, or solve a CAPTCHA. This requirement may vary, according to the variant of the commenting form, used by the blog.

Now, a blog owner has 4 choices, to control anonymous comments.
  1. Don't allow anonymous comments, and don't require a CAPTCHA. People who are not logged in will have to login, to comment.
  2. Don't allow anonymous comments, but require a CAPTCHA. People who have not logged in will have to login, and solve a CAPTCHA.
  3. Allow anonymous comments, and don't require a CAPTCHA. People who have not logged in will have to either login, or solve a CAPTCHA.
  4. Allow anonymous comments, and require a CAPTCHA. People who are not logged in will have to solve a CAPTCHA.

Some people will have to either login, or solve a CAPTCHA, to comment. Depending upon what choices are made by the blog owner, the readers may have any 2 of 3 choices.
  1. Solve a non owner optional reCAPTCHA.
  2. Solve an owner optional ezCAPTCHA.
  3. Login.
You'll like the ezCAPTCHA a lot more than the reCAPTCHA.

People who are logged in to Blogger / Google, and are not subject to third party cookie filters, may not see a CAPTCHA - and will not have to login to comment. People who are logged in, but are subject to third party cookie filters, will have to either login, or solve a CAPTCHA.

Owners of blogs which attract readers, who choose to maintain their cookie filters, will benefit more from the new CAPTCHA, than owners of blogs which attract readers who do not choose - or do not care - to maintain their cookie filters.

To make the choices easier to understand, Blogger would have to make "Require CAPTCHA" a binary option, for at least 3 comment authentication levels.
  1. Anonymous.
    • Require CAPTCHA.
    • Don't require CAPTCHA.
  2. OpenID.
    • Require CAPTCHA.
    • Don't require CAPTCHA.
  3. Google account.
    • Require CAPTCHA.
    • Don't require CAPTCHA.
  4. Members.
    • Require CAPTCHA.
    • Don't require CAPTCHA.

If Blogger were to offer this binary option, too many owners would select "Anonymous" / "Don't require CAPTCHA" - and spammers would continue to flood the spam filters - as they were, before the latest update.

As long as spammers choose to do business - and choose to target our blogs, in their business - our choices, as blog owners and readers, will be limited.

>> Top

Sunday, November 16, 2014

Confusion About GMail Vs Non GMail Based Email

Long ago, when diagnosing a problem thought to involve email, in Blogger Help Forum: Get Help with an Issue, we would ask a very simple question
Is your Blogger account based on a GMail - or non GMail - email address?
And we would carefully add
Please, do not state your email address, here!
The latter request was to prevent theft of peoples Blogger accounts.

Now, in many cases, we must qualify the question of email address. We also ask.
Is your email provided by your employer, ISP, or school network?
and even
Do you read your email in a browser window, or a local email client?

Modern email distribution is not always homogeneous.

Both questions reflect the complex nature of email delivery, that is a part of Internet reality.

Few people can accurately diagnose their problems, based only on the simple question
Is your Blogger account based on a GMail - or non GMail - email address?
The lines between GMail, and non GMail email accounts - and addresses - are not absolute, any more.

Both GMail and non GMail addresses may be used in a local network.

GMail, and non GMail addresses, alike, may use GMail browser based email, in delivery and display. And GMail accounts may use non GMail email systems, for addressing, delivery, and / or display.

These variations can lead to interesting scenarios such as mysterious loss of blog membership invitations, and of email subscriptions. And options for Blogger account recovery become more complicated - with password synchronisation issues, between the email account and the Blogger account.

Thanks to Google Apps based domains, and the ability to provide non GMail addresses which use GMail, anybody can use a non GMail address with GMail based delivery and display. Some people have even setup Blogger accounts, based on Google Apps based email addresses (again, appearing to be non GMail based) - though this is not recommended.

Managed domains may use GMail delivery, and a non GMail email address.

Corporate email systems, ISP provided email, and schools (of all grades, elementary through university) may use Google Apps based email. Many large local network based email systems have been "upgraded" to use cloud based email, such as GMail, for delivery and display. The results are not always beneficial.

And, thanks to "push / pull" GMail options, where an individual GMail account can be configured by a knowlegeable account owner, even individual account owners can use a GMail address, with non GMail delivery and display - or can use GMail display, for non GMail based address / delivery.

With computer owners who do not care or know about what email system they use, with where the individual messages may be filed, and with security filters that update without notice, loss of email messages is common.

Bounced email does not get dropped into the "Bulk" / "Spam" folder.

Note that "bounced" email may not be treated as spam. Some "bounced" email never gets as far as a spam filter - it may simply be rejected. You will look, in vain, in the "Bulk", "Inbox", and "Spam" folders.

This will interfere with account recovery - if you can't find the password reset email, how do you recover control of the account?

The simple question
Is your Blogger account based on a GMail - or non GMail - email address?
just is not accurate, when diagnosing all Blogger problems.

Friday, November 14, 2014

Comments Posted Use "noreply" Email Addresses

Recently, we've noted a number of complaints about Blogger commenting, in Blogger Help Forum: Something Is Broken
.My comments all use a "noreply" email address, instead of my actual email address. How do I have people email their replies to my comments?
This appears to be one more way which Blogger is trying to safeguard our Blogger accounts and blogs, from malicious, technically astute blog thieves.

Some time ago, we observed that this precaution appeared to be unique to Blogger accounts which used Google and Google+ profiles - and did not involve Blogger profiles.

It appears that this is now universal, and includes Blogger profiles, as well as Google / Google+ profiles. It's likely that the noreply email addresses are being offered to keep more blog readers from, inadvertently, exposing their email addresses to email mining techniques.

In remembering the long ago discovered "nice blog" spam, it's possible that "nice blog" spam was originally developed to help the spammers gather email addresses, using very innovative technique.

All that a spammer has to do is to post a "nice blog" comment, select "Email follow-up comments to me" - then watch as the Inbox fills up with follow up comments from bloggers, willingly giving up their email addresses to every stranger also selecting "Email follow-up comments to me", in that comment thread.

The people willingly providing their email addresses, to the world in general, are perfect targets for hackers later trying to brute force access to the Blogger accounts, starting from the provided email addresses. Use of the "no-reply" email address prevents this type of mischief - and reduces the workload of Google Security, as they would otherwise have to verify account / blog integrity, for hacked accounts and blogs.

For even more protection (which is not a bad idea, in any case), consider using Google 2-Step Verification, to protect your Blogger / Google account from hacking.

>> Top

Wednesday, November 12, 2014

The CAPTCHA, For Anonymous Comments, Isn't Going Away

Several weeks ago, Blogger added a security feature to Blogger commenting, to reduce comment spam.
Note: Even if you don't have word verification turned on, anonymous commenters might be asked to enter some text. This helps protect your blog from abuse.

This change has not pleased everybody.
I disabled "prove you're not a robot" for commenting. Why do my readers still have to solve a CAPTCHA, each time they comment?
This blog owner is not looking at the bigger picture. This new feature will benefit many blog owners - when Blogger is used, properly.

By adding a CAPTCHA, to the option to allow anonymous comments, we get several benefits.
  • People can allow anonymous comments, without allowing uncontrolled spammer activity.
  • People can allow authenticated comments, and not require a CAPTCHA.
  • The overall level of spam, currently being seen on some blogs which allow anonymous comments and require no CAPTCHA, will drop. This will allow Blogger Security engineers the chance to concentrate, more intently, on the remaining spam.
Instead of restricting the ability for people to comment on our blogs, this change actually increases the ability for people to comment - and decreases the spam.

People who are logged in to Blogger - and who are visible as logged in - won't even see the new CAPTCHA, even if they want to comment anonymously. Only people who are not logged in (or who are not seen as logged in), and who wish to comment without logging in, will be inconvenienced.

The biggest problem, with the new CAPTCHA form, is with people who are seeing the CAPTCHA even when logged in - because they are filtering "third party" cookies. Those people will have the choice of logging in again, or solving the CAPTCHA.

Anybody who is not logged in can avoid having to solve the CAPTCHA, even if one is presented, by logging in to Blogger. Since the standard Google "One account" login is used, people who do not have a Blogger account can setup one, on the fly, in a couple of minutes. This option is not obvious, from the commenting form - especially with the CAPTCHA displayed - but it is present.

Since the commenting form comes in 4 versions, depending upon template type and comment form placement, Blogger Engineering will need to make a coordinated effort, to improve the overall design of the comment form.

The various buttons and links, which allow the comments to be published using the many options, will have to be displayed better - to make it apparent to everybody that logging in to Blogger can avoid use of the CAPTCHA - even if the reader wishes to not identify, by commenting anonymously. And, other improvements are needed, also.

And once again, I will point out that a better user experience will be had by all who can properly maintain their computers, and not block "third party" cookies. Anybody, who is able to login to Blogger, should be able to comment anonymously, without inconvenience of the CAPTCHA.

Some solutions in Blogger require our action - not just action by Blogger Engineering.

>> Top

Tuesday, November 11, 2014

The "Reply" Option, For Embedded Comments

The option provided some time ago, to the embedded comment form, to allow "threaded" comments, is becoming quite popular.

Unfortunately, the "Reply" link does not always work. Blog owners and readers alike complain.
I click on "Reply", and nothing happens!
This problem appears to have accelerated recently, possibly resulting from the hasty rollout of the new anonymous comments CAPTCHA - but there are other less obvious possibilities, too.

The threaded comments "Reply" feature, a seemingly minor addition to the Blogger code base, can have problems with a number of issues.

  • A Full Blog Feed.
  • An up to date post template,
  • The Google "One account" login, and cookie filtering.
  • The recent addition of the anonymous commenting CAPTCHA.
  • The threaded comments script, and recent script filter updates.

A Full blog feed is required.

Many blog owners are not aware that the "Reply" option won't be available, without a Full Blog Feed. Go to the dashboard, and look at "Allow Blog Feed", under Settings - Other - Site feed.

For threaded comments, you will need a Full Blog Feed (for both comments and posts) - and this will exclude private blogs.


Any "Allow Blog Feed" selection, other than "Full", will be a problem.



An up to date post template is a good idea.

Threaded comments, like every other post and comment feature, works best on an up to date post template. Any time threaded comments stops working, and you have not changed the blog feed, try resetting the post template. Now, here's hoping that you have not made extensive post template tweaks.

The identity of the person who wants to reply is useful.

Threaded Blogger hosted comments code, like threaded Google+ hosted comments, other commenting scripts, and many other Blogger features, needs access to the login cookie, to identify the person preparing to comment. Because of the use of the Google "One account" login, "third party" cookie filters must be examined.

Anything that interferes with the CAPTCHA will be a problem.

The recent addition of the anonymous comment CAPTCHA, appears to have caused some problems. This may be an matter for Blogger Engineering to correct.

Anything that interferes with scripts will be a big problem.

All Blogger scripts, including the script which services the "Reply" link, are subject to script filtering. Script filters are subject to update, on every different client computer - generally without notice to the computer owner. Always check script filters.

Blog owners and readers, alike, need to be aware of the issues, to use Blogger effectively. Threaded comments are no exception to this requirement.

Tuesday, October 28, 2014

Comments And Cookie Filters - October 2014

The new, mandatory CAPTCHA form, for blog readers wishing to comment anonymously, has been in service for just under a week.

We're seeing a variety of problems, reported in Blogger Help Forum: Get Help with an Issue, by blog owners and readers alike.

Long ago, for blogs with readers who were not really comfortable with maintaining security on their computers, we would recommend changing comment form placement.

The full page (or the slightly less preferable popup window) comment form was more usable, with readers who do not know how to properly maintain cookie and script filters. With recent changes in Blogger and Google, all Blogger comment forms are now vulnerable to inappropriate filters.
  • Use of the Google "One account" login creates login cookies under "google.com" - not "blogger.com".
  • Publishing blogs to custom domains - not "blogspot.com" - makes cookie access "third party".
  • Referencing blogs from countries subject to country code aliasing - not as "blogspot.com" - makes cookie access "third party".
  • The new, mandatory commenting CAPTCHA form, part of all Blogger comment form placement options, makes cookie access very important.
All of these issues, considered together, makes proper third party cookie filtering even more critical, than it has been, in the past - and makes new Blogger features more problematic.

The Google "One account" login, at "google.com", is now used by many blog owners and readers - instead of the Blogger native login, at "blogger.com". When the "blogger.com" login was used, cookies created under "blogger.com" were not as vulnerable, to cookie filters.

Whether used under "blogspot.com", or whatever country code alias or custom domain is in use (for the embedded comment form) - or under "blogger.com" (for the full page and popup window comment forms) - login cookies created under "google.com" (by the Google "One account" login) are vulnerable to "third party" cookie filters.

Blogs published to custom domains are becoming more and more popular. All blogs published to custom domains, which use the embedded comment form, are vulnerable to "third party" cookie filters.

Blogs referenced under country code aliasing are becoming more normal. All blogs subject to country code alias redirection are vulnerable to "third party" cookie filters.

The new, mandatory commenting CAPTCHA form needs to access the Blogger / Google login cookie - so blog readers, who are logged in to Blogger / Google, will not be subject to the CAPTCHA. The embedded, full page, and popup window forms are equally vulnerable to "third party" cookie filters, given the above discussed issues.

Thanks to the Google "One account" login, as Blogger is made a way of life to more of a reader population who have no interest in maintaining security on their computer, these issues will become more problematic.

>> Top

Sunday, October 26, 2014

The New Commenting CAPTCHA Is Inconsistent

The new CAPTCHA, added by Blogger last week to restrict spam in anonymous comments, is already showing signs of unwanted effect, with some blogs.

Besides making the commenting sequence more complicated, the sequence, in general, is inconsistent. Differences in the sequence, when compared between the three commenting form placement options (embedded, popup, and full page), varied by the original CAPTCHA screening option, and the moderation option, have been noted. And how many readers, commenting on their favourite blog, will think of hitting "Publish" with "Google account" selected, to login and avoid the CAPTCHA?

The CAPTCHA form itself will discourage comments, being made by the casual blog reader, against many blogs. And the CAPTCHA, as added to all three comment forms, now makes cookie filtering issues equally critical, for the embedded, popup, and full page forms, alike.

As designed, CAPTCHA screening should simply affect people who wish to publish comments, anonymously.

Some blogs may require the CAPTCHA, for anonymous and authenticated comments, alike - when a reader is not logged in to Blogger. Other blogs may allow people to avoid the CAPTCHA, altogether - who even comment, anonymously, without solving a CAPTCHA, when logged in.

With some blogs, you may hit the "Publish" button immediately, and go straight to login - and other times, be stopped by the refusal
Comment should not be empty
Alternately, you may compose your comment, then select "Google account" - and upon returning from login, find an empty comment window.

Depending upon which comment placement option / template type is in use, you may see any of those inconsistencies.
  • Dynamic template.
  • Embedded.
  • Full page.
  • Pop-up window.
Each of these different comment forms variants has its own peculiarities.

These inconsistencies are more critical, because some readers filter cookies, improperly. With third party cookies filtered, the login status is not correctly identified by the commenting process - and the CAPTCHA may be required where it should not apply.

We may even see, with enough different people trying to comment, a return of the commenting login loop - where people login, repeatedly, but are denied by the CAPTCHA form in the commenting process.

Making things still worse, the CAPTCHA form is nasty. People who are less technically astute, and who have problems maintaining the filters on their computer, may be less tolerant of the CAPTCHA process - and may simply find other blogs, maybe outside Blogger / Google in general, which are more permissive.

The need for the CAPTCHA form, in general, is real - but the implementation needs improvement. Until unimproved, many Blogger blogs will feel negative effects.

>> Top

Navigate» Become author for this Blog