3 ms·
I don't consider getting access to a website via the most insecure blogging platform on the internet "hacking".
by mrkris 13y ago
I don't consider getting access to a website via the most insecure blogging platform on the internet "hacking".
- thirsteh 13y ago[citation needed] WordPress isn't that insecure. A lot of third-party (i.e. written by inexperienced developers) plugins for it are, though.
- jblz 13y agoNot sure why you say that. WordPress.com offers 2-Factor Auth: http://en.support.wordpress.com/security/two-step-authentication/ http://en.support.wordpress.com/security/two-step-authentica... There are also tons of available security plugins & pretty extensive documentation on hardening a self-hosted install: http://wordpress.org/plugins/tags/security http://wordpress.org/plugins/tags/security http://codex.wordpress.org/Hardening_WordPress http://codex.wordpress.org/Hardening_WordPress
- krapp 13y agoStill, a lot of what's on that page and a lot of the common features of plugins like Wordfence (which I use) should be part of the core, I think. Though also in my opinion even having a web-based file editor is pretty terrible...
- X4 13y agoHardening Wordpress. That made me speechless………… But hey, what do I know? ¯\_(ツ)_/¯ Only the tip of the iceberg. Some men believe. https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=wordpress https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=wordpress
- krapp 13y agoHow much of what's on that list actually applies to a recent version of Wordpress?
- X4 13y ago>> to a recent version of Wordpress Saying recent here isn't logical, because after patching the incident, it's not an incident anymore. But I guess you mean how secure you are with a recent version of Wordpress. I think this is though question, because Wordpress relies to a high degree on external components and plugins. There is probably no single pure Wordpress Blog, because the original Wordpress archive already relies heavily on external dependencies. That's where many of the issues were found as correctly pointed out by wyck. However this reliance on external code, without a Wordpress team or at least a software that is evaluating the code-quality or any other metric, you can't be secure. Yeah we can argue with: "But Wordpress is n-times more popular than X." However it still makes WP very vulnerable to attacks. I've cleaned and recovered some hacked commercial wp blogs and shops myself (not installed by me, but the previous dev). So whatever you believe in WP may be, just get over it. There are so many other opensource alternatives that wait for you to be tried out.
- krapp 13y agoShow me an alternative that I can sell to a non-technically minded client with a small business who just wants to blog and put up a youtube feed and do e-commerce and maybe SEO. And oh, they can't ever even know what a terminal is, much less git.
- gregmolnar 13y agoWhy should the client know git or anything else if you are the one who has to setup the blog for him/her? Or are you working with clients only who know html, css, ftp etc so they can do the work themself just being lazy and paying you instead?
- krapp 13y agoI think they don't want to be intimidated by complexity and don't want to have to pay someone more to deal with it for them in the future. Typically they want to be able to administrate the site themselves, and they can do that through web forms easily enough.
- wyck 13y agoNot much because those are plugins and not WordPress, there are over 27k of them on .org and probably another 5-10k hosted on other sites.
- mrkris 13y agoHaving 2-Factor auth is meaningless if you can bypass the auth itself.
- corresation 13y agoI doubt the purported "insecurity" of Wordpress has anything to do with this. Given that they simultaneously defaced a multitude of social media outlets for Skype, it seems fairly likely that they phished or compromised someone who managed social media accounts.