5 ms·
I look forward to new 0-day hacks and admin vulnerabilities!
by askedrelic 16y ago
I look forward to new 0-day hacks and admin vulnerabilities!
- steveklabnik 16y agoWhile I agree with you... what to use instead? It seems that all the other CMS/blogging platforms have the same issues...
- deleted 16y ago[deleted]
- jauer 16y agoMovableType seems to not have as many issues.
- photomatt 16y agoIt also seems to have not as many users.
- pcarmichael 16y agoI'll take that over constantly having to upgrade my install or recovering from being hacked.
- mitchellhislop 16y agoReally? You will take a less vibrant, less helpful, and less forward-moving community over WP because you cant set it up right?
- weego 16y agoHow forward-moving do you need a system that allows you to manage content within site templates to be?
- aasarava 16y agoJust because there aren't as many known exploits for MT doesn't mean it's more secure than WP. That's the same argument used when people say Apple software is more secure than Microsoft software. Yet if Apple software was used by more than 90%+ of businesses, it's likely more people would attempt to (and possibly find ways to) hack it. Security aside, MT has lots of issues -- performance (or lack thereof) being one of them and bad upgrades being another. After the third time an upgrade broke some sites I manage, I gave up and migrated some sites to WordPress and some to Drupal. Have yet to come across the same issue.
- ck2 16y agoMT does not disclose many security issues and instead slips fixes quietly into new releases.
- callahad 16y agoStatic site generators using Disqus for comments seem to be quite popular in certain circles.
- steveklabnik 16y agoIt's true, I used to use Jekyll myself. Unfortunately, this won't work for the site I'm building for my girlfriend's father...
- tjpick 16y agoI gave my GF's mother a weebly site. She loves it.
- nuclear_eclipse 16y agoMy father is now running his site on Weebly too, and he thinks it's fantastic.
- sjs382 16y agoI use WordPress + wget as a static site generator for a client of mine. Works wonders. :) Headed to Refresh Pittsburgh tonight? There's a presentation about WP3.
- askedrelic 16y agoWhoa, someone else from Pittsburgh? I've been looking for hackers/tech culture around Pittsburgh and haven't managed to find too much so far. I think I will check this out tonight.
- steveklabnik 16y agoCheck out my project, http://pghtechevents.com/ http://pghtechevents.com/ ;)
- sjs382 16y agohttp://www.refreshpittsburgh.org/ http://www.refreshpittsburgh.org/ There are events pretty much every month, but I haven't made any in a while this will be my first Refresh Pittsburgh all year. Make sure ya say hello to this guy: http://bit.ly/9jELdY http://bit.ly/9jELdY (me) Might want to add RefreshPittsburgh, Devhouse Pittsburgh and Dorkbot Pittsburgh to the events calendar, too.
- steveklabnik 16y agoIiiinteresting. That sounds terrible... but awesome. I didn't know it was happening tonight. Maybe. We'll see. I've been on a roll with Hackety Hack lately, and I want to make sure I have a few hours to put in.
- photomatt 16y agoCome on guys -- it's been a while. We oversee or advise on blogs for basically every major media site (CNN, WSJ, NYT, IHT, TechCrunch, GigaOM...) as well as running WordPress myself (and WP.org) for 7+ years and have never had an application level exploit. If WP was really as insecure as you suggest, all of the news sites would look like 4chan. It's possible to run WP in a secure manner. Just because some people don't doesn't mean you can't. It doesn't require crazy wget hacks, just updating. You can even automate it with SVN. If anyone has questions or would like best practices for running WP in a secure manner, I'd be happy to answer them, here or over email -- m@mullenweg.com.
- dcurtis 16y agoYou should make running WordPress securely a thoughtless process. The best practices should be clearly explained to every single user who downloads/installs it.
- photomatt 16y agoSure -- the simplest way to keep it secure is just keep it updated. To this end we work with numerous third-party hosts to help them update their customers, and have invested significantly in a notification and upgrade system for 10k+ plugins, 1k+ themes, and of course the core software. This was a particular PITA because runs on so many platforms with wildly different constraints and configurations. We blog, tweet, and email 200k people whenever there's a new release and offer free help on our forums to anyone who is stuck. Someday we might even offer auto-update in core just like many hosts already do. My comment was more aimed at the HN audience which might want pro tips for staying updated or more defense in depth. For example I have a cron job run `svn up` on my site every morning which keeps it up to date whether I'm in front of my computer or on a beach sipping mai tais.
- chaosmachine 16y ago"I have a cron job run `svn up` on my site every morning" Can you really trust that not to randomly break your site? Surely you'll run into regressions or backwards-incompatibilities at some point?