intertwingly

It’s just data

Secure Blogging by Email


Ben Hammersley: Being able to prove ownership, or at least definitive origination, would be an excellent ability to have. And once again, it's the blogging world who are getting up and actually doing it, small piece by small piece.

I actually think the sweet spot is in comments. How I chose to update my weblog is of an academic interest to most, but the ability to author new content is of a much wider interest. At the moment, the best I can say is that a given comment is purported to be by Ben or Mark or Shelley or whoever.

But I would prefer to start this much more incrementally. The most basic thing comments by email provide is the ability to download various RSS feeds, hit the road, and respond while disconnected. If you want to try this, you can do it on this blog entry.

The next thing people will want is the ability to specify a URL of their homepage to be displayed instead of their e-mail address. Much discussion will ensue as to whether this should be a MIME header or in the body. If defacto standards emerge in this area, I will simply support both.

Signing is the next step, particularly given that e-mail clients already tend to have built in support for this. Ultimately, when the spam starts arriving, only signed e-mails will be accepted.

Services are the next step. If I can validate a signature against some data located via a link from your home page, I would be comfortable with providing Jabber messages whenever additional comments are made to a blog entry that you have commented on. Or on processing signed requests to update or delete weblog entries that you originated.

Update: I've changed the address to be blog-1172 instead of blog:1172 so that email clients need not quote the address per RFC 822