From Dave to Ben to Bill to Justin to Eric, an idea is forming on how to do decentralized and secure comments. Stripping away all the implementation details here's the basics as I see them:

I like the idea of validating against something I can find in somebody's weblog. I'd also like to suggest that instead of sending back responses and presuming that the recipient is online, that I merely produce a personalized feed and leave it on my server to be fetched whenever the client desires.

There's a nice idea in there, making the identity part of the user's weblog. I like that.

I'm gonna go out on a limb here and predict that Dave's solution will not use PGP, REST, LINK, RSS 1.0, RDF, or FOAF, because, respectively, it's overly complex, it's overly simplistic, it requires an HTML parser, it's evil, it's evil incarnate, and it's the fruit of a poisonous tree.

