4 ms·
No, either you don't get it or you refuse to. WP 2.8, WP 2.7, WP 2.5 etc. each were compromised almost immediately and each time several security updates have
by onreact-com 17y ago
No, either you don't get it or you refuse to.
WP 2.8, WP 2.7, WP 2.5 etc. each were compromised almost immediately and each time several security updates have been issued in the matter of days and weeks.
Nobody can keep up with it so no wonder WordPress blogs get hacked.
Why don't they just release stable and secure versions?
- gjm11 17y agoWhy? Because security is hard to do unless you (1) build it in right from the start and (2) are good at it, and neither of those things appears to be true in the case of WordPress. You appear to be suggesting -- I can't tell how seriously -- that WordPress is deliberately made insecure so that when Automattic (ugh, I hate that name) want people to upgrade they always have a security issue they can use to scare people into doing so. Sorry, but that's absolutely nuts. (In case it isn't clear: I am not, in the least, defending WP's security record. I am pointing out that the things you're saying here are crazy.)
- onreact-com 17y ago"You appear to be suggesting -- I can't tell how seriously -- that WordPress is deliberately made insecure so that when Automattic (ugh, I hate that name) want people to upgrade they always have a security issue they can use to scare people into doing so. Sorry, but that's absolutely nuts" No, YOU said that. I just said they don't care enough for security. Otherwise they wouldn't spit out new versions with holes so often. So there is no reason to insult me. Also the WordPress people pointing out all the time how wordpress.com hasn't been hacked is just obvious advertising for their hosted services.
- gjm11 17y agoOK, so we're at cross purposes. It looks to me like (1) I misunderstood something you said but (2) it still (2a) doesn't make sense and (2b) is distinctly more than "I just said they don't care enough for security". Specifically: you said "This is the way they advertise for their wordpress.com version obviously. Stick with us or you get compromised." So, my mistake: I interpreted "their wordpress.com version" as "the latest version" rather than "hosting your blog on wordpress.com". That was dumb of me; sorry. On the other hand, even after fixing my brain in that respect, I still can't see any way to read that as just saying that "they don't care enough for security". If in fact it's true that wordpress.com consistently gets updated immediately when a new version comes out that fixes a security problem, and that people hosting their own WordPress blogs tend to be sluggish about upgrading, then I don't see why one of the things they say when a compromise happens is "you'd be in much less danger on wordpress.com". Because, y'know, it's true. What would be improper would be if (1) they are deliberately putting out insecure code to make their hosted version more appealing, or (2) the only thing they say when a security problem comes up is "come and use our hosted version". #1 is what it still looks to me like you were saying, but seems immensely improbable, not least because I find it very hard to believe that their net gain in paying customers from an incident like this one is positive. #2 would be bad. indeed; is it true?