Friday, May 01, 2009

Blogger comment bug allows anyone to delete comments

It would appear that Google/Blogger have either inadvertently introduced a serious bug to their comment system or they've added a feature intended to drive popular blogs away from using "Anonymous" comment posting.

It now appears that if you are not logged in and view the comments in a Blogger blog then the system will allow you delete any comment on someone else's blog if it is either (a) Anonymous or (b) has a Name/URL entered by the user.

The following screenshot was taken in Epiphany whilst not logged in to Blooger. You will see that I had the option - via the little rubbish bin - to delete comments on my blog even though I was, in effect, just an ordinary person browsing the site and should have no access level to do it.


This is what appears after you delete a comment that is either anonymous or simply filled in with a Name/URL.

That's like an epic fail on Blogger's part if it is not a deliberate move to get people registering on sites.

Feel free to start deleting any of the comments that you can on this blog if you must. I don't really mind.

Update: Tracking suggests the nice people at Google now know. Perhaps they can mail me when its fixed?



Update II: Word reaches me that Google are on it. What that means I don't know.

Update III: For anyone wondering what this bug is actually doing, it seems to be that Blogger is assuming that a comment that is not made by someone logging into a formal ID handle is "anonymous" therefore anyone browsing the site without being logged in is "anonymous" too, ergo you are the author of the anonymous comments on all Blogger sites. Nice!

Update IV: This bug was fixed by Google with a rollout of new code Friday afternoon. Apologies for the late update.

25 comments:

  1. This comment has been removed by the author.

    ReplyDelete
  2. This comment has been removed by the author.

    ReplyDelete
  3. Thats because they are registered comment maker with google accounts and not anons or named.

    ReplyDelete
  4. This comment has been removed by the author.

    ReplyDelete
  5. Thanks for that tip. I have just been over to Iain Dale's Diary and deleted the comment by Verity which was insulting to me and appears to have been ignored by the blog author even though he claims to have a policy of not allowing commenters to either insult Iain Dale or other commenters.

    ReplyDelete
  6. This comment has been removed by the author.

    ReplyDelete
  7. Stu isn't anon but it has a trash can under it so I could delete that as well as the anon above this post!!
    Shall I ? ;o)

    ReplyDelete
  8. Appears to be sorted. Dolly behind it?

    ReplyDelete
  9. This comment has been removed by the author.

    ReplyDelete
  10. This comment has been removed by the author.

    ReplyDelete
  11. anon@14:33 said
    "it's fun this"

    Isn't it just :)

    ReplyDelete
  12. This comment has been removed by the author.

    ReplyDelete
  13. This comment has been removed by the author.

    ReplyDelete
  14. This comment has been removed by the author.

    ReplyDelete
  15. This comment has been removed by the author.

    ReplyDelete
  16. This comment has been removed by the author.

    ReplyDelete
  17. @Kate 15:03 "Hi Dizzy I alerted Ian ;-) the thing is not only can you delete but when you hit the bin and the little message comes up anyone could change what you say and then it cancel. Therefore what you wrote under your profile if you are not logged in could be changed to anything."

    Unless Google have changed the system, which I don't see they have, you cannot post edit a comment.

    ReplyDelete
  18. This comment has been removed by the author.

    ReplyDelete
  19. Humpty_Dumpty: Hmmm, for some reason it doesn't work for me, logged in or out - I'm using FF. Do you have to post first?

    ReplyDelete
  20. This post has been removed by the author.

    ReplyDelete
  21. Is it fixed? Testing testing...

    ReplyDelete
  22. Dizzy,

    I'm sure you've seen this but I thought the blogging implications were interesting:

    WolframAlpha – Blogging Revolution

    ReplyDelete
  23. http://www.ed-hardy.cc/

    ReplyDelete
  24. http://www.edhardy-zone.com/
    http://www.ed-hardy.cc/

    ReplyDelete
  25. Where did my previous comment go?

    ReplyDelete