3 ms·
Not surprisingly, I disagree. First of all, you are lumping WordPress the open source software and WordPress.com the hosted service together. My post is about W
by tonischneider 16y ago
Not surprisingly, I disagree. First of all, you are lumping WordPress the open source software and WordPress.com the hosted service together. My post is about WordPress.com which uses the continuous deployment model and has a very solid security track record (as good or better than any other large scale web service like Facebook, GMail, etc). Also, our fast deployment model helps to very quickly fix whatever problems there may. Finally, though I can't speak for WordPress.org because it's separate from Automattic, they have developed a very effective model of responding to security issues and auto-notifying and -updating people.
- jerf 16y ago"First of all, you are lumping WordPress the open source software and WordPress.com the hosted service together." Yes I am, and I apologize. I did not realize there was much of a distinction. I would edit away much of my message now if I could. But... "Also, our fast deployment model helps to very quickly fix whatever problems there may." Security problems do not work that way. Rapid deployment does not recover your user database that the hacker got, just as one example. Rapid deployment may close XSS holes, but doesn't undo the damage they did while open. And you don't need rapid deployment to close XSS anyhow, historically lots of people have managed that without rapid deployment. I still see it as potentially beneficial on some fronts but an enormous risk on other fronts I care about a lot.
- rm-rf 16y agoIs wordpress.org a different code base?