@Adam Rosenfield: I'm glad I wasn't the only one that thought that right away when reading this post. Sure, they used a crappy *hash* that's been known weak since the 90s, but they still called crypt(), and didn't just store the passwords in the clear. This is the one huge failing that I can see.
Your solution (require login) seems to do the trick. Another very "analog" method that I use is to save my comment in the clipboard while I log in to such things. Seems like if the login was "ajaxy" you could just store the comment without passing it around though.
Mar 2, 2010