10 ms·
Improving WordPress Password Security
- digitalengineer 11y agoIt's even worse. Why can someone just keep trying to login on default WP installation? Why can they try to guess usernames? First thing I install is: https://www.wordfence.com https://www.wordfence.com
- throwaway21816 11y ago$10 has been deposited into your wordfence affiliate account. Thank you, have a good day.
- poopsintub 11y agoDownvoting a throwaway account. Stooping to new levels.
- dang 11y agoWe've banned this account for repeatedly breaking the HN guidelines.
- snowwrestler 11y agoDoes Wordpress still not have basic rate limiting on forms?
- krapp 11y agoIt does not.
- CLGrimes 11y agoEven still, default login attempts are set at 20. I've had a lot of recent bruteforce attacks, and set that delimiter to 5. On top of that, I try changing the wp-login location with 'rename wp-login'[1], and set it to something like http://www.site.com/hello http://www.site.com/hello . Doesn't stop everyone, but helps cut down attempts. [1]https://wordpress.org/plugins/rename-wp-login/ https://wordpress.org/plugins/rename-wp-login/
- lightlyused 11y agoEnumerating evil is never the correct solution.
- mgkimsal 11y ago"WordPress’ core team stance on bumping the PHP version requirement is two fold: 1. Too many WP users are still on old versions like 5.2 and 5.3 2. They don’t care about new "features"" If you really do power 20%+ of the websites out there, do you not perhaps have enough influence to influence a change? I could almost buy this reasoning 6-7 years ago. "If we start requiring PHP 5.1... all our users might flock to something else that still only needs 4.3! We better not push things too much". A large segment of the hosting world caters to the wordpress user (casual and professional) and they will jump to whatever requirements Wordpress puts out. Where are they going to go? No one will want to upset this golden goose. WP, make version 5.0 require PHP 7 and be done with it. People will upgrade. They have no real choice - you've killed most any platform that might be a serious competitor for the next several years.
- bretthopper 11y agoWe (the Roots team) have had this same opinion for years now. I feel that WordPress underestimates the power they have. Now WordPress does actually work with a lot of the top hosting companies to get their PHP versions upgraded. They do this quietly but they do talk about it from time to time. But they don't go nearly far enough with this outreach program and by still allowing 5.2 and not setting any deprecation timelines it really hurts their efforts.
- mgkimsal 11y agoInteresting to know, but... man... they've got some opportunity with PHP hitting a 7.0 and there not being a WP 5.0 released yet. Upgrading PHP isn't just about using "new features" - WP doesn't even have to use any new stuff, but still require higher versions for security and speed benefits would help move the web forward a lot.
- paulddraper 11y agoI don't think the web needs PHP in order to move forward.
- tomschlick 11y agoWordpress really needs to move to git/github/gitlab. The fact that in 2016 all of the plugins are part of a massive single svn repository is insane. They would probably see a 10x improvement on contributions by moving to github/gitlab almost overnight, potentially fixing these stupid issues. As mgkimsal said, they should also take a hard stance and require PHP 7 for version 5.0. The speed improvements alone would be worth it.
- Eric_WVGG 11y agoI’d like to see them handle it similarly to the jQuery 1.x -> 2 fork (feature freeze + bug fixes in perpetuity for the former, all new development and bumped requirements in the latter).
- jlgaddis 11y agoPeople say the same thing about OpenBSD (WRT CVS) but, if it works just fine for them, who's to say what they should (or "need") to use.
- mgkimsal 11y ago"who's to say what they should use" Those of us who have to clean up after it, and those of us who've had to deal with spam and malware-infested wordpress sites interfering with our business. Much like google/gmail, windows, and other large monopoly-like players, wordpress is a huge impact on a lot of businesses; whether those businesses are using wordpress or not, we still feel the impact (and yes, I am using it for a couple projects as well - chmod 400 on pretty much the whole site unless I'm doing updates).
- The_Magistrate 11y agoGreat article! I had no idea that Wordpress still deployed on such outdated versions of PHP. I moved away from Wordpress years ago, but it's always great to see the community pushing to make everything more secure.
- anexprogrammer 11y agoBlimey, it's taken until now to get bcrypt in Wordpress? What the heck took them so long?
- jammycakes 11y agoWhat's more shocking is that not only are they not using bcrypt, they're still using MD5. Correct me if I'm wrong, but aren't there organisations being prosecuted in some jurisdictions for having password security that weak?
- anexprogrammer 11y agoWouldn't surprise me, it's had lots of exposure with all the data leaks. I last looked at passwords sometime in 2010 off the back of the infamous "use bcrypt" post. Just skimmed the WP ticket, what a horrible amount of effort to cover an edge case of people regressing to a 4 years past dead PHP version.
- Eric_WVGG 11y agoread it again, Wordpress still doesn’t have it. These guys just got fed up and provided a workaround.
- anexprogrammer 11y agoOops, too much skimming. Kudos to the roots folks for getting involved and sorting it.
- ajsalminen 11y ago"Roots has long been critics of the out-dated PHP version requirements in WordPress. They still have 5.2 as the minimum version which has been end of life (EOL) since January 6th 2011." This is ignoring the fact that distributions provide security updates for older versions. Looks like RHEL5 includes PHP 5.1 and it's possible to get support for it until 2020.
- nikolay 11y agoSo, just when well over one year ago Argon2 won the password hashing competition [0], we still advice for bcrypt? [0]: https://password-hashing.net/ https://password-hashing.net/
- nikolay 11y agoWordPress just needs to break compatibility and launch a new version with different requirements (such as PHP 7+ and MySQL 5.7+) and leave a couple of guys just doing security fixes for legacy versions. Now it's such a weird mix of functions, globals, classes, and it's just terrible to have such a vastly popular product being so poorly written and architected! Abusing MySQL to store vast amounts of metadata in wp_options and other tables when NoSQL databases have been available for years is outrageous!
- teh_klev 11y ago> when NoSQL databases have been available for years is outrageous! I work for a shared hoster, we host a ton of WordPress sites. The problem here is that in shared hosting world MySQL is ubiquitous, along with PHP. It's all you need to get your WordPress blog up and running. Adding a dependency on a NoSQL datastore breaks that simplicity. Also which NoSQL database do you target because not all of them are suitable for running in these types of environments. Also wp_options is, as the table name suggests, mostly just option settings which are looked up by a known key "option_name" then the json-like blob is read from the "option_value" field and parsed. There's very little or no searching done for values inside that blob so you're adding NoSQL complexity just to store key/value pairs. MySQL is a well known, well understood thing and "just works" for apps like WordPress.
- nikolay 11y agoThis problem could easily be solved by adapters. You can have a default adapter storing this into MySQL tables, but open it up for databases that are designed to do just that effectively. Oh, well, WordPress doesn't even support PostgreSQL, which alone can do both pretty effectively. There's os much spaghetti code in WordPress that I always have a bad feeling pushing that code to Production (with capital "P"). A lot of people praise WordPress for the great number of plugins and themes, but the reality is that only 1% of those are quality code, forward-compatible, following best practices, secure, and suitable for use and not just getting something out of the door quickly. That's why WordPress needs rethinking and most importantly - some sandboxing of themes at least because you can't even allow a shared hosting to upload custom themes as most of them can hack your entire infrastructure being plain PHP code. I can't believe WordPress being such an archaic product, why they don't support Smarty-based themes, which could be execution-safe.