With yesterday's change combined with the changes made today I am feeling a little more secure about things. Yesterday, I added random keys to each post that have to be submitted along with any comment made. Today, in order to keep from these simply being enumerated and used later, I added a cron script that will change these keys a couple of times a day. In addition to that, posting attempts can now only be made from a single ip address once every minute. This should help eliminate potential spam problems. I know there are still attacks against the page, but hopefully they are frustrating enough to annoy anyone enough not to bother.
I am hoping that the time enforcement won't cause too much annoyance for out honest posters. Originally, the time was going to be set for 2 minutes, but I figured that would get annoying really fast. Besides, all these times can be changed later.




