3 ms·
AFAIK wordpress.com never got broken into...
by nir 17y ago
AFAIK wordpress.com never got broken into...
- tptacek 17y agoThat feels extremely unlikely.
- pwmanagerdied 17y agoI felt the same, but after searching for a few minutes I wasn't able to find anything to contradict it. It looks like their hosted option may actually be significantly more secure than installing your own.
- simonk 17y agoWordpress.com is up to date on the Wordpress software, only blogs that haven't updated since the last 2 versions are open for attack.
- tsally 17y agohttp://en.wikipedia.org/wiki/Zero_day_attack http://en.wikipedia.org/wiki/Zero_day_attack
- mahmud 17y agoIf they're lucky, someone competent pwned them and he is now doing a great job defending his turf. Everybody gets owned, kept or rm'ed; just a matter of time.
- onreact-com 17y agoThis is the way they advertise for their wordpress.com version obviously. Stick with us or you get compromised. Bad style. They rather should fix their buggy software. They prefer new features over security. Have you noticed how with each major upgrade there are new holes in it? WordPress is like Swiss cheese, full of holes. I'd prefer Swiss banks or watches instead.
- gjm11 17y agoLet me just rephrase that first paragraph a little. "When a WordPress security problem is found, they release a new version with the problem fixed and say everyone should upgrade to it. That's bad. Instead, they should release a new version with the problem fixed." Doesn't something about that seem a little ... odd ... to you?
- onreact-com 17y agoNo, either you don't get it or you refuse to. WP 2.8, WP 2.7, WP 2.5 etc. each were compromised almost immediately and each time several security updates have been issued in the matter of days and weeks. Nobody can keep up with it so no wonder WordPress blogs get hacked. Why don't they just release stable and secure versions?
- gjm11 17y agoWhy? Because security is hard to do unless you (1) build it in right from the start and (2) are good at it, and neither of those things appears to be true in the case of WordPress. You appear to be suggesting -- I can't tell how seriously -- that WordPress is deliberately made insecure so that when Automattic (ugh, I hate that name) want people to upgrade they always have a security issue they can use to scare people into doing so. Sorry, but that's absolutely nuts. (In case it isn't clear: I am not, in the least, defending WP's security record. I am pointing out that the things you're saying here are crazy.)
- onreact-com 17y ago"You appear to be suggesting -- I can't tell how seriously -- that WordPress is deliberately made insecure so that when Automattic (ugh, I hate that name) want people to upgrade they always have a security issue they can use to scare people into doing so. Sorry, but that's absolutely nuts" No, YOU said that. I just said they don't care enough for security. Otherwise they wouldn't spit out new versions with holes so often. So there is no reason to insult me. Also the WordPress people pointing out all the time how wordpress.com hasn't been hacked is just obvious advertising for their hosted services.
- onreact-com 17y agowordpress.com blogs get hacked as well, just check: http://www.google.com/search?q=wordpres.com+hcked&pws=0&hl=all&num=10 http://www.google.com/search?q=wordpres.com+hcked&pws=0&... You'll find threads like these: http://en.forums.wordpress.com/topic/my-site-got-hacked http://en.forums.wordpress.com/topic/my-site-got-hacked http://en.forums.wordpress.com/topic/my-friends-site-was-hacked http://en.forums.wordpress.com/topic/my-friends-site-was-hac... http://en.forums.wordpress.com/topic/i-got-hacked-1 http://en.forums.wordpress.com/topic/i-got-hacked-1 where wordpress.com users seek help after they got hacked.
- pwmanagerdied 17y agoPlease read links before you post them in future. I did the same search. In each of those cases it seems like being "hacked" means adding another admin and having them screw you over or having your password guessed. Though I'm no Wordpress fan, blaming them for things like that is rather absurd.
- photomatt 17y agoWP.com, to my knowledge, has never had a code or security breach. There are communities (like Club Penguin) where they are quite promiscuous with their passwords and share login details with each other regularly, and then "hack" each others blogs.