4 ms·
I'm curious, what the answers to the comparisons you mentioned would make you conclude positively in WordPress's favor? Is security based on the number of user
by dotBen 13y ago
I'm curious, what the answers to the comparisons you mentioned would make you conclude positively in WordPress's favor?
Is security based on the number of users of your application?
1 in 6 websites on the Internet runs WordPress.
Is security based on the number of publicly disclosed vulnerabilities as compared to competitors?
It's open source code so every discovered vulnerability is public knowledge. Many competitors are closed source and may not disclose vulnerabilities (doesn't mean there aren't any). On this point, I'm not sure what could be improved on given it's FOSS or what "winning" would look like.
Is security based on some formally-definable metric that can be created by examination of the code itself?
If you can come up with the metric, I'm sure it can given the code is FOSS. Perhaps I don't follow what you're looking for here.
Is security based on some financial guarantee from the backers of an application?
It's Free Open Source Software, no FOSS I know of has a financial guarantee by its very nature. Examples like RHEL are not free (as in beer). The guarantee of FOSS comes from the degree of sunshine placed upon the code that everyone has an aligned interest to disclose vulnerabilities.
Perhaps you could elaborate on what would make you feel "X is secure"?
- carbocation 13y ago> I'm curious, what the answers to the comparisons you mentioned would make you conclude positively in WordPress's favor? My goal in disqualifying myself at the beginning of my post was to make it clear that, although I find the article to be unconvincing (the reasons for which I tried to explain), I'm not the one (at least, not given how little I've thought about it) to come up with a good way to decide what it should mean to say "X is secure." Unfortunately this means that answering my questions isn't probably a good use of your time, because to me they were off-the-cuff. (Oddly, I had answered one of the questions that you responded to.) The list is not exhaustive. It was a mix of real questions (code metrics) and anti-questions (# of users) that was unfortunately not very logically laid out. They were just what came to mind while waiting for a 5x5' storage unit rental to get cleaned out. To be moved, I think people want to see relevant data. Unfortunately I don't have more to offer about what that looks like than Potter Stewart did.
- tptacek 13y agoThere is a universe of terribly unsafe open source software. The notion that Wordpress is somehow more secure because it has a different license than phpBB is wishful.
- wglb 13y agoIt's open source code so every discovered vulnerability is public knowledge. Well, there is public knowledge, and there is actual action. Several examples come to mind. OpenSSL, which has been available for a very long time, does not have that good a track record. There is the example of 10-year old vulnerabilities disclosed in TOSSA that only recently came to light. The BEAST attack's underlying target was written about before. From the point of view of labeling anything to be "secure" (whatever that means), I like to think what Steve Brown used to say about some new output from his science lab: "Not known not to work". Translated to the security world, "Not known to have security vulnerabilities."