Techcrunch moves from Rackspace to Wordpress Hosting
centernetworks.com
centernetworks.com
They handle everything, which makes keeping a site up even easier than using RackSpace. Their support team is very knowledgeable about WordPress, which is a huge plus.
However, they take an Apps Store approach- they review every line of code. (I even once had Matt Mullenweg himself show up on a few commits; he changed the use of "Wordpress" in a few comments to the proper "WordPress")
This is problem. Their server is quirky- they have a lot of extra, mostly undocumented code (code that isn't part of WordPress), as well as some weird PHP settings. So, it wasn't rare for changes (that were thoroughly tested on our dev site) to break the site for no apparent reason. It would take a few hours to a few days to get the changes reverted.
There are lots of processes running on the machines and if someone uploads malicious code or bad performing code, it could be detrimental to other blogs on the same machine or machines or sets of machines which may even be managed by Rackspace, who knows, and databases all working together. Systems at that scale are constantly evolving to fend off hackers from within the wordpress community and outside it. From within the network and beyond the firewall.
Rackspace has their own set of problems lower in the stack than wordpress. Lower in the stack than any application specific code, be it within wordpress's open source or a JavaScript library, a custom website for a mobile phone or image processing.
There is going to be a dedicated VIP portal with documentation of all the special functions, lots of theme and system info, and best practice coding guidelines for WP.com.
The cool thing about VIP is you can get, say, a direct link from the Yahoo home page and it doesn't break a sweat. It's specialized to just WordPress, but more people every day are running their entire site through WP.
I am finding Cloud Servers to be a great system, especially when you have load balancing and backend servers that don't use any non-local bandwidth. at $10/mo for a 256MB slice compared to $20/mo for slicehost, it is a good deal if you need a lot of small workers.
1. Write horribly insecure free/open source blog software. Become massively popular.
2. Wait for peoples' blogs to start getting hacked. Users then realize they can't / don't want to keep up with the alarmingly frequent vulnerabilities / patches, and turn to wordpress.com to handle hosting.
3. Profit!
I host and keep 6 blogs up to date like this for friends and together with things like mod_security I've never had a problem with spam or being hacked.
I realise this is just anecdotal and isolated, but an upgrade doesn't get much simpler than "svn up".
And you can this to automatically install via SVN http://birdhouse.org/software/2008/04/wp-create/ (and there's a similar script for updating all the sites at once)
I personally use FastCGI+SUExec to ensure that WordPress' PHP code executes under a specific user account other than Apache's. It does not address the possibility of WordPress code itself somehow being hacked, but it does provide some sort of sandbox protection to the site.
I'm not thrilled with WordPress' past security track record, but I think they have made it so easy to use that a lot of users simply throw the scripts up on a shared server without knowing exactly what they're doing so far as server configuration goes. I wonder how many WordPress blogs are exploited because of a stupid permission setup?
Here's where a lot of the security problems arise. As I mentioned, a lot of people are on a shared host and using mod_php. The only way they can make their files writable is to somehow give Apache write access to them. That opens up the possibility for other sites on the shared server to execute PHP that also writes to these files.
If you're stuck in this position, I'd recommend as a hack/workaround, to temporarily chown the files to www-data/apache. Perform the upgrade, then change ownership of the files back.
Ideally, if you're setting up your own server, I'd recommend FastCGI/SUExec:
http://www.howtoforge.com/how-to-set-up-apache2-with-mod_fcg...
You have much finer-grained control over how your PHP can execute. Alternatively, although I have no experience with it, you could try suphp to achieve a similar effect but by sticking with mod_php.
I always see this on HN, but no one ever bothers to elaborate. Can you please do so?
http://secunia.com/advisories/product/6745/?task=advisories_...
And that only illustrates the broader point here: WordPress is open source and incredibly widely used, so typically vulnerabilities are found and patched pretty fast. For 99.9% of people, there's not really a better alternative.
I don't know of any current zero-day exploits in Windows either... Does that logically mean that Windows is a rock-solid platform?
Also, there are no better alternatives to WordPress? A hundred startups and blog platforms would disagree! There certainly are quite a few more secure alternatives. I personally use Bloggart on App Engine. :)
If you were an oracle database customer, wouldn't you outsource your oracle database management to oracle before you'd outsource it to microsoft?
It's a trade off. There is some software I'll gladly host myself. Wordpress is not one of them.
Wordpress didn't just magically "Become massively popular", it got so because it served many people's needs (there were plenty of alternative free/OSS blogging engines all along). Its developers put in thousands of hours' unpaid work before monetizing became an possibility.
Providing supported/hosted services based on an open source solution, while continuing to release your work as open source, is about as noble as a business model can be, IMHO.
An up-to-date WordPress, which is easier than ever using the built-in upgraders, is secure. There are more bad sysadmins in the world than people who can't click the upgrade button.
It's not surprising GigaOm is so tightly integrated into Wordpress.com - it's more surprising a competitor like TC now is.
I wish they would explain more why they made this move. For a tech website, I didn't even know what Wordpress VIP was and had to look it up myself.
http://benmetcalfe.com/blog/2010/01/wordpress-to-be-currentl... and also http://news.ycombinator.com/item?id=1077311
I'd imagine the move has more to do with wordpress.com actively updating the software vs. hw / network infrastructure.
Am I wrong in assuming that TechCrunch was hosted on CloudSites?
Support is handled by a worldwide team of some of the nicest and sharpest people you'll ever meet, with escalation to the core people behind WordPress. We've seen and worked with more high-profile blogs than probably anyone else.
The typical floor for VIP is 1 million pageviews a month. Many clients do many times that, or host dozens of sites with us.