- 43
- Sphinn It!
Posted By: WebGeek 187 days ago
Topic Type: News Story (Jump to http://www.hybrid6.com)
Category: Blogging
17 Comments
17 Comments
Save the date for:
SMX London - Nov. 4-5: Pre-agenda rate now available. Click here.
SMX West - Feb. 10-12
Learn more about search marketing through free online webcasts and webinars from our sister site Search Marketing Now.
Comments
While I agree blindly upgrading is not a wise idea security by obscurity is not exactly a wise idea either ;)
Agreed, and note, I only included as as an option for people who are concerned about being kicked out of Technorati. I definitely wouldn't stop there. :)
The irony http://sphinn.com/story/40051
However it should be stated that this may effect previous versions as well
Yeah, I noticed that. :)
I agree 100% with this article. I hate any kind of interference or dictation by third parties in what I do with my websites. If I want to use WordPress, then I don't want to be strong armed into using the version that suits someone else, anymore than I want to have to speed up the loading times of landing pages because Google thinks it's a good idea.
I KNOW what's best for my sites and my business.
I'm not so sure I agree with the point about not being able to choose specific versions. I moved over to the Subversion method, and using svn, you can select the distribution you want to install here:
http://svn.automattic.com/wordpress/tags/
It made updating to 2.5 nearly effortless, when the instructions were followed.
http://codex.wordpress.org/Installing/Updating_WordPress_with_Subversion
This is a lot of FUD. Nobody is strong-arming anybody, the vulnerabilities in legacy WordPress installations are being rampantly exploited. My full response is here http://www.arachna.com/roller/page/spidaman/20080411#fear_uncertainty_and_disinformation_about
@brian: I didn't say you couldn't upgrade to a specific version - Notice I said that a large # of bloggers are not famililiar with that process, and that it wouldn't be practical for a lot of bloggers to upgrade to version 2.3.3 specifically.
@arachna: It's absolutely not FUD.
spidaman -
Uhhh, yes it is strong-arming and a major fear tactic. Even though Technorati delivers a pittance of traffic compared to other sources for most blogs, it will freak unknowledgeable persons out to the point they may irrationally upgrade to 2.5. Which I did on a personal blog with little traffic just to test it, and it broke my theme. And then an old theme I switched to, yeah, that was broken, too.
There are other solutions which would handle the issue Technorati cares about, and their solution of forcing upgrades is so easily worked around this policy does more harm than good.
Cough moderators can we get a moderator !
:) no oh well,
when the comment above this one is deleted this comment will no longer make sense.
@tnash I saw it too Tim... Damn! Now we both look daft ;)
Sorry, it is FUD because it's full of inaccuracies about what measures Technorati has specifically implemented, illogical arguments about where the greater risks are and mixes in code stewardship arguments (API compatibility, etc) with security ones. Anyway, you can keep your head in the sand about it or read the full story here http://www.arachna.com/roller/page/spidaman/20080411#fear_uncertainty_and_disinformation_about
No need to be rude. If your policies are indeed misrepresented, then perhaps you should clarify them for the public, on the Technorati official blog, because the messages being transmitted on your official blog are contrary to what you're saying.
@spidaman -
Now that securityfocus.com is reporting that 2.5 suffers from multiple sql injections vulnerabilities in wp-comments-post.php, do you have any plans to amend this statement?
Since, you know, despite being illogical it actually is still not more secure, and all that good stuff...
That securityfocus posting connects some data points for me, I've seen that exploit in action but on older WP installations. Since securityfocus is saying all WP versions are vulnerable, that changes the picture.
So, is that a yes you will plan to ammend your post?
nm, I see the new post. :)